_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EED2Ev:
   64|  40.6k|      ~AlignmentBuffer() { secure_zeroize_buffer(m_buffer.data(), sizeof(T) * m_buffer.size()); }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EEC2Ev:
   62|  11.7k|      AlignmentBuffer() = default;
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE5clearEv:
   71|  53.8k|      void clear() {
   72|  53.8k|         zeroize_buffer(m_buffer.data(), m_buffer.size());
   73|  53.8k|         m_position = 0;
   74|  53.8k|      }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE21handle_unaligned_dataERNS_12BufferSlicerE:
  166|  57.3k|      [[nodiscard]] std::optional<std::span<const T>> handle_unaligned_data(BufferSlicer& slicer) {
  167|       |         // When the final block is to be deferred, we would need to store and
  168|       |         // hold a buffer that contains exactly one block until more data is
  169|       |         // passed or it is explicitly consumed.
  170|  57.3k|         const size_t defer = (defers_final_block()) ? 1 : 0;
  ------------------
  |  Branch (170:31): [True: 0, False: 57.3k]
  ------------------
  171|       |
  172|  57.3k|         if(in_alignment() && slicer.remaining() >= m_buffer.size() + defer) {
  ------------------
  |  Branch (172:13): [True: 28.3k, False: 29.0k]
  |  Branch (172:31): [True: 3.26k, False: 25.0k]
  ------------------
  173|       |            // We are currently in alignment and the passed-in data source
  174|       |            // contains enough data to benefit from aligned processing.
  175|       |            // Therefore, we don't copy anything into the intermittent buffer.
  176|  3.26k|            return std::nullopt;
  177|  3.26k|         }
  178|       |
  179|       |         // Fill the buffer with as much input data as needed to reach alignment
  180|       |         // or until the input source is depleted.
  181|  54.1k|         const auto elements_to_consume = std::min(m_buffer.size() - m_position, slicer.remaining());
  182|  54.1k|         append(slicer.take(elements_to_consume));
  183|       |
  184|       |         // If we collected enough data, we push out one full block. When
  185|       |         // deferring the final block is enabled, we additionally check that
  186|       |         // more input data is available to continue processing a consecutive
  187|       |         // block.
  188|  54.1k|         if(ready_to_consume() && (!defers_final_block() || !slicer.empty())) {
  ------------------
  |  Branch (188:13): [True: 10.6k, False: 43.4k]
  |  Branch (188:36): [True: 10.6k, False: 0]
  |  Branch (188:61): [True: 0, False: 0]
  ------------------
  189|  10.6k|            return consume();
  190|  43.4k|         } else {
  191|  43.4k|            return std::nullopt;
  192|  43.4k|         }
  193|  54.1k|      }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE18defers_final_blockEv:
  233|  81.8k|      constexpr bool defers_final_block() const {
  234|  81.8k|         return FINAL_BLOCK_STRATEGY == AlignmentBufferFinalBlock::must_be_deferred;
  235|  81.8k|      }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE6appendENSt3__14spanIKhLm18446744073709551615EEE:
   90|  96.2k|      void append(std::span<const T> elements) {
   91|  96.2k|         BOTAN_ASSERT_NOMSG(elements.size() <= elements_until_alignment());
  ------------------
  |  |   84|  96.2k|   do {                                                                     \
  |  |   85|  96.2k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  96.2k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 96.2k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  96.2k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 96.2k]
  |  |  ------------------
  ------------------
   92|  96.2k|         std::copy(elements.begin(), elements.end(), m_buffer.begin() + m_position);
   93|  96.2k|         m_position += elements.size();
   94|  96.2k|      }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE24elements_until_alignmentEv:
  221|   225k|      size_t elements_until_alignment() const { return m_buffer.size() - m_position; }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE16ready_to_consumeEv:
  231|   198k|      bool ready_to_consume() const { return m_position == m_buffer.size(); }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE7consumeEv:
  200|  56.3k|      [[nodiscard]] std::span<const T> consume() {
  201|  56.3k|         BOTAN_ASSERT_NOMSG(ready_to_consume());
  ------------------
  |  |   84|  56.3k|   do {                                                                     \
  |  |   85|  56.3k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  56.3k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 56.3k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  56.3k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 56.3k]
  |  |  ------------------
  ------------------
  202|  56.3k|         m_position = 0;
  203|  56.3k|         return m_buffer;
  204|  56.3k|      }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE12in_alignmentEv:
  226|   128k|      bool in_alignment() const { return m_position == 0; }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE23aligned_data_to_processERNS_12BufferSlicerE:
  126|  13.8k|      [[nodiscard]] std::tuple<std::span<const uint8_t>, size_t> aligned_data_to_process(BufferSlicer& slicer) const {
  127|  13.8k|         BOTAN_ASSERT_NOMSG(in_alignment());
  ------------------
  |  |   84|  13.8k|   do {                                                                     \
  |  |   85|  13.8k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  13.8k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 13.8k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  13.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 13.8k]
  |  |  ------------------
  ------------------
  128|       |
  129|       |         // When the final block is to be deferred, the last block must not be
  130|       |         // selected for processing if there is no (unaligned) extra input data.
  131|  13.8k|         const size_t defer = (defers_final_block()) ? 1 : 0;
  ------------------
  |  Branch (131:31): [True: 0, False: 13.8k]
  ------------------
  132|  13.8k|         const size_t full_blocks_to_process = (slicer.remaining() - defer) / m_buffer.size();
  133|  13.8k|         return {slicer.take(full_blocks_to_process * m_buffer.size()), full_blocks_to_process};
  134|  13.8k|      }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE18fill_up_with_zerosEv:
   79|  45.7k|      void fill_up_with_zeros() {
   80|  45.7k|         if(!ready_to_consume()) {
  ------------------
  |  Branch (80:13): [True: 45.2k, False: 444]
  ------------------
   81|  45.2k|            zeroize_buffer(&m_buffer[m_position], elements_until_alignment());
   82|  45.2k|            m_position = m_buffer.size();
   83|  45.2k|         }
   84|  45.7k|      }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE20directly_modify_lastEm:
  113|  42.1k|      std::span<T> directly_modify_last(size_t elements) {
  114|  42.1k|         BOTAN_ASSERT_NOMSG(size() >= elements);
  ------------------
  |  |   84|  42.1k|   do {                                                                     \
  |  |   85|  42.1k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  42.1k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 42.1k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  42.1k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 42.1k]
  |  |  ------------------
  ------------------
  115|  42.1k|         return std::span(m_buffer).last(elements);
  116|  42.1k|      }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE4sizeEv:
  217|  42.1k|      constexpr size_t size() const { return m_buffer.size(); }

_ZN5Botan10ct_is_zeroITkNSt3__117unsigned_integralEhEET_S2_:
   37|  4.29k|BOTAN_FORCE_INLINE constexpr T ct_is_zero(T x) {
   38|  4.29k|   return ct_expand_top_bit<T>(~x & (x - 1));
   39|  4.29k|}
_ZN5Botan17ct_expand_top_bitITkNSt3__117unsigned_integralEhEET_S2_:
   28|  4.29k|BOTAN_FORCE_INLINE constexpr T ct_expand_top_bit(T a) {
   29|  4.29k|   const T top = CT::value_barrier<T>(a >> (sizeof(T) * 8 - 1));
   30|  4.29k|   return static_cast<T>(0) - top;
   31|  4.29k|}
_ZN5Botan17ct_expand_top_bitITkNSt3__117unsigned_integralEmEET_S2_:
   28|  25.9k|BOTAN_FORCE_INLINE constexpr T ct_expand_top_bit(T a) {
   29|  25.9k|   const T top = CT::value_barrier<T>(a >> (sizeof(T) * 8 - 1));
   30|  25.9k|   return static_cast<T>(0) - top;
   31|  25.9k|}
_ZN5Botan10ct_is_zeroITkNSt3__117unsigned_integralEmEET_S2_:
   37|  25.4k|BOTAN_FORCE_INLINE constexpr T ct_is_zero(T x) {
   38|  25.4k|   return ct_expand_top_bit<T>(~x & (x - 1));
   39|  25.4k|}
_ZN5Botan6chooseITkNSt3__117unsigned_integralEmEET_S2_S2_S2_:
  216|  1.15k|BOTAN_FORCE_INLINE constexpr T choose(T mask, T a, T b) {
  217|       |   //return (mask & a) | (~mask & b);
  218|  1.15k|   return (b ^ (mask & (a ^ b)));
  219|  1.15k|}
_ZN5Botan8high_bitITkNSt3__117unsigned_integralEjEEmT_:
   73|  3.33k|BOTAN_FORCE_INLINE constexpr size_t high_bit(T n) {
   74|  3.33k|   size_t hb = 0;
   75|       |
   76|  19.9k|   for(size_t s = 8 * sizeof(T) / 2; s > 0; s /= 2) {
  ------------------
  |  Branch (76:38): [True: 16.6k, False: 3.33k]
  ------------------
   77|       |      // Equivalent to: ((n >> s) == 0) ? 0 : s;
   78|  16.6k|      const size_t z = s - ct_if_is_zero_ret<T>(n >> s, s);
   79|  16.6k|      hb += z;
   80|  16.6k|      n >>= z;
   81|  16.6k|   }
   82|       |
   83|  3.33k|   hb += static_cast<size_t>(n);
   84|       |
   85|  3.33k|   return hb;
   86|  3.33k|}
_ZN5Botan17ct_if_is_zero_retITkNSt3__117unsigned_integralEjEEmT_m:
   45|  16.6k|BOTAN_FORCE_INLINE constexpr size_t ct_if_is_zero_ret(T x, size_t s) {
   46|       |   /*
   47|       |   Similar to `return ct_is_zero(x) & s` but has to account for possibility that
   48|       |   sizeof(T) is smaller than sizeof(size_t) which would lead to incomplete masking
   49|       |   */
   50|  16.6k|   const T a = ~x & (x - 1);
   51|  16.6k|   const size_t a_top = static_cast<size_t>(CT::value_barrier<T>(a >> (sizeof(T) * 8 - 1)));
   52|  16.6k|   const size_t mask = static_cast<size_t>(0) - a_top;
   53|  16.6k|   return mask & s;
   54|  16.6k|}
_ZN5Botan17ct_if_is_zero_retITkNSt3__117unsigned_integralEmEEmT_m:
   45|  35.4k|BOTAN_FORCE_INLINE constexpr size_t ct_if_is_zero_ret(T x, size_t s) {
   46|       |   /*
   47|       |   Similar to `return ct_is_zero(x) & s` but has to account for possibility that
   48|       |   sizeof(T) is smaller than sizeof(size_t) which would lead to incomplete masking
   49|       |   */
   50|  35.4k|   const T a = ~x & (x - 1);
   51|  35.4k|   const size_t a_top = static_cast<size_t>(CT::value_barrier<T>(a >> (sizeof(T) * 8 - 1)));
   52|  35.4k|   const size_t mask = static_cast<size_t>(0) - a_top;
   53|  35.4k|   return mask & s;
   54|  35.4k|}
_ZN5Botan6chooseITkNSt3__117unsigned_integralEjEET_S2_S2_S2_:
  216|  7.44M|BOTAN_FORCE_INLINE constexpr T choose(T mask, T a, T b) {
  217|       |   //return (mask & a) | (~mask & b);
  218|  7.44M|   return (b ^ (mask & (a ^ b)));
  219|  7.44M|}
_ZN5Botan8majorityITkNSt3__117unsigned_integralEjEET_S2_S2_S2_:
  222|  3.72M|BOTAN_FORCE_INLINE constexpr T majority(T a, T b, T c) {
  223|       |   /*
  224|       |   Considering each bit of a, b, c individually
  225|       |
  226|       |   If a xor b is set, then c is the deciding vote.
  227|       |
  228|       |   If a xor b is not set then either a and b are both set or both unset.
  229|       |   In either case the value of c doesn't matter, and examining b (or a)
  230|       |   allows us to determine which case we are in.
  231|       |   */
  232|  3.72M|   return choose(a ^ b, c, b);
  233|  3.72M|}
_ZN5Botan8high_bitITkNSt3__117unsigned_integralEmEEmT_:
   73|  5.90k|BOTAN_FORCE_INLINE constexpr size_t high_bit(T n) {
   74|  5.90k|   size_t hb = 0;
   75|       |
   76|  41.3k|   for(size_t s = 8 * sizeof(T) / 2; s > 0; s /= 2) {
  ------------------
  |  Branch (76:38): [True: 35.4k, False: 5.90k]
  ------------------
   77|       |      // Equivalent to: ((n >> s) == 0) ? 0 : s;
   78|  35.4k|      const size_t z = s - ct_if_is_zero_ret<T>(n >> s, s);
   79|  35.4k|      hb += z;
   80|  35.4k|      n >>= z;
   81|  35.4k|   }
   82|       |
   83|  5.90k|   hb += static_cast<size_t>(n);
   84|       |
   85|  5.90k|   return hb;
   86|  5.90k|}

_ZN5Botan13reverse_bytesITkNSt3__117unsigned_integralEjQooooooeqstT_Li1EeqstS2_Li2EeqstS2_Li4EeqstS2_Li8EEES2_S2_:
   25|   321k|inline constexpr T reverse_bytes(T x) {
   26|       |   if constexpr(sizeof(T) == 1) {
   27|       |      return x;
   28|       |   } else if constexpr(sizeof(T) == 2) {
   29|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap16)
   30|       |      return static_cast<T>(__builtin_bswap16(x));
   31|       |#else
   32|       |      return static_cast<T>((x << 8) | (x >> 8));
   33|       |#endif
   34|   321k|   } else if constexpr(sizeof(T) == 4) {
   35|   321k|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap32)
   36|   321k|      return static_cast<T>(__builtin_bswap32(x));
   37|       |#else
   38|       |      // MSVC at least recognizes this as a bswap
   39|       |      return static_cast<T>(((x & 0x000000FF) << 24) | ((x & 0x0000FF00) << 8) | ((x & 0x00FF0000) >> 8) |
   40|       |                            ((x & 0xFF000000) >> 24));
   41|       |#endif
   42|       |   } else if constexpr(sizeof(T) == 8) {
   43|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap64)
   44|       |      return static_cast<T>(__builtin_bswap64(x));
   45|       |#else
   46|       |      uint32_t hi = static_cast<uint32_t>(x >> 32);
   47|       |      uint32_t lo = static_cast<uint32_t>(x);
   48|       |
   49|       |      hi = reverse_bytes(hi);
   50|       |      lo = reverse_bytes(lo);
   51|       |
   52|       |      return (static_cast<T>(lo) << 32) | hi;
   53|       |#endif
   54|       |   }
   55|   321k|}
_ZN5Botan13reverse_bytesITkNSt3__117unsigned_integralEtQooooooeqstT_Li1EeqstS2_Li2EeqstS2_Li4EeqstS2_Li8EEES2_S2_:
   25|  43.2k|inline constexpr T reverse_bytes(T x) {
   26|       |   if constexpr(sizeof(T) == 1) {
   27|       |      return x;
   28|  43.2k|   } else if constexpr(sizeof(T) == 2) {
   29|  43.2k|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap16)
   30|  43.2k|      return static_cast<T>(__builtin_bswap16(x));
   31|       |#else
   32|       |      return static_cast<T>((x << 8) | (x >> 8));
   33|       |#endif
   34|       |   } else if constexpr(sizeof(T) == 4) {
   35|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap32)
   36|       |      return static_cast<T>(__builtin_bswap32(x));
   37|       |#else
   38|       |      // MSVC at least recognizes this as a bswap
   39|       |      return static_cast<T>(((x & 0x000000FF) << 24) | ((x & 0x0000FF00) << 8) | ((x & 0x00FF0000) >> 8) |
   40|       |                            ((x & 0xFF000000) >> 24));
   41|       |#endif
   42|       |   } else if constexpr(sizeof(T) == 8) {
   43|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap64)
   44|       |      return static_cast<T>(__builtin_bswap64(x));
   45|       |#else
   46|       |      uint32_t hi = static_cast<uint32_t>(x >> 32);
   47|       |      uint32_t lo = static_cast<uint32_t>(x);
   48|       |
   49|       |      hi = reverse_bytes(hi);
   50|       |      lo = reverse_bytes(lo);
   51|       |
   52|       |      return (static_cast<T>(lo) << 32) | hi;
   53|       |#endif
   54|       |   }
   55|  43.2k|}
_ZN5Botan13reverse_bytesITkNSt3__117unsigned_integralEmQooooooeqstT_Li1EeqstS2_Li2EeqstS2_Li4EeqstS2_Li8EEES2_S2_:
   25|  45.7k|inline constexpr T reverse_bytes(T x) {
   26|       |   if constexpr(sizeof(T) == 1) {
   27|       |      return x;
   28|       |   } else if constexpr(sizeof(T) == 2) {
   29|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap16)
   30|       |      return static_cast<T>(__builtin_bswap16(x));
   31|       |#else
   32|       |      return static_cast<T>((x << 8) | (x >> 8));
   33|       |#endif
   34|       |   } else if constexpr(sizeof(T) == 4) {
   35|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap32)
   36|       |      return static_cast<T>(__builtin_bswap32(x));
   37|       |#else
   38|       |      // MSVC at least recognizes this as a bswap
   39|       |      return static_cast<T>(((x & 0x000000FF) << 24) | ((x & 0x0000FF00) << 8) | ((x & 0x00FF0000) >> 8) |
   40|       |                            ((x & 0xFF000000) >> 24));
   41|       |#endif
   42|  45.7k|   } else if constexpr(sizeof(T) == 8) {
   43|  45.7k|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap64)
   44|  45.7k|      return static_cast<T>(__builtin_bswap64(x));
   45|       |#else
   46|       |      uint32_t hi = static_cast<uint32_t>(x >> 32);
   47|       |      uint32_t lo = static_cast<uint32_t>(x);
   48|       |
   49|       |      hi = reverse_bytes(hi);
   50|       |      lo = reverse_bytes(lo);
   51|       |
   52|       |      return (static_cast<T>(lo) << 32) | hi;
   53|       |#endif
   54|  45.7k|   }
   55|  45.7k|}

_ZN5Botan12BufferSlicerC2ENSt3__14spanIKhLm18446744073709551615EEE:
   25|  59.2k|      explicit BufferSlicer(std::span<const uint8_t> buffer) : m_remaining(buffer) {}
_ZNK5Botan12BufferSlicer5emptyEv:
   68|   181k|      bool empty() const { return m_remaining.empty(); }
_ZN5Botan12BufferSlicer9take_byteEv:
   57|  43.4k|      uint8_t take_byte() { return take(1)[0]; }
_ZN5Botan12BufferSlicer4takeEm:
   37|   118k|      std::span<const uint8_t> take(const size_t count) {
   38|   118k|         BOTAN_STATE_CHECK(remaining() >= count);
  ------------------
  |  |   51|   118k|   do {                                                         \
  |  |   52|   118k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */             \
  |  |   53|   118k|      if(!(expr)) {                                             \
  |  |  ------------------
  |  |  |  Branch (53:10): [True: 0, False: 118k]
  |  |  ------------------
  |  |   54|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */    \
  |  |   55|      0|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   56|      0|      }                                                         \
  |  |   57|   118k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (57:12): [Folded, False: 118k]
  |  |  ------------------
  ------------------
   39|   118k|         auto result = m_remaining.first(count);
   40|   118k|         m_remaining = m_remaining.subspan(count);
   41|   118k|         return result;
   42|   118k|      }
_ZNK5Botan12BufferSlicer9remainingEv:
   66|   214k|      size_t remaining() const { return m_remaining.size(); }

_ZN5Botan13nibble_to_hexEh:
   76|     56|inline constexpr char nibble_to_hex(uint8_t b) {
   77|     56|   const uint8_t n = b & 0x0F;
   78|     56|   return static_cast<char>(n < 10 ? '0' + n : 'A' + (n - 10));
  ------------------
  |  Branch (78:29): [True: 39, False: 17]
  ------------------
   79|     56|}

base64.cpp:_ZN5Botan11base_decodeINS_12_GLOBAL__N_16Base64EEEmRKT_PhPKcmRmbb:
  124|     92|                   bool ignore_ws = true) {
  125|       |   // TODO(Botan4) Check if we can use just base. or Base:: here instead
  126|     92|   constexpr size_t decoding_bytes_in = std::remove_reference_t<Base>::decoding_bytes_in();
  127|     92|   constexpr size_t decoding_bytes_out = std::remove_reference_t<Base>::decoding_bytes_out();
  128|       |
  129|     92|   input_consumed = 0;
  130|       |
  131|     92|   uint8_t* out_ptr = output;
  132|     92|   std::array<uint8_t, decoding_bytes_in> decode_buf{};
  133|     92|   size_t decode_buf_pos = 0;
  134|     92|   size_t final_truncate = 0;
  135|     92|   bool seen_padding = false;
  136|       |
  137|     92|   clear_mem(output, base.decode_max_output(input_length));
  138|       |
  139|  3.16k|   for(size_t i = 0; i != input_length; ++i) {
  ------------------
  |  Branch (139:22): [True: 3.08k, False: 80]
  ------------------
  140|  3.08k|      const uint8_t bin = base.lookup_binary_value(input[i]);
  141|       |
  142|       |      // This call might throw Invalid_Argument
  143|  3.08k|      if(base.check_bad_char(bin, input[i], ignore_ws)) {
  ------------------
  |  Branch (143:10): [True: 1.55k, False: 1.53k]
  ------------------
  144|       |         // Padding may only appear at the end, so a data symbol must never
  145|       |         // follow one (0x81 marks a padding character)
  146|  1.55k|         if(seen_padding) {
  ------------------
  |  Branch (146:13): [True: 7, False: 1.54k]
  ------------------
  147|      7|            throw Invalid_Argument(base.name() + " decoding failed, data follows padding");
  148|      7|         }
  149|  1.54k|         decode_buf[decode_buf_pos] = bin;
  150|  1.54k|         ++decode_buf_pos;
  151|  1.54k|      } else if(bin == 0x81) {
  ------------------
  |  Branch (151:17): [True: 259, False: 1.27k]
  ------------------
  152|    259|         seen_padding = true;
  153|    259|      }
  154|       |
  155|       |      /*
  156|       |      * If we're at the end of the input, pad with 0s and truncate
  157|       |      */
  158|  3.08k|      if(final_inputs && (i == input_length - 1)) {
  ------------------
  |  Branch (158:10): [True: 3.04k, False: 36]
  |  Branch (158:26): [True: 39, False: 3.00k]
  ------------------
  159|     39|         if(decode_buf_pos) {
  ------------------
  |  Branch (159:13): [True: 22, False: 17]
  ------------------
  160|     22|            const size_t bits_per_symbol = base.bits_consumed();
  161|     22|            const size_t pad_bits = (decode_buf_pos * bits_per_symbol) % 8;
  162|       |
  163|       |            // A trailing symbol contributing only pad bits cannot occur in a
  164|       |            // valid encoding; RFC 4648 4 and 6 enumerate the reachable cases
  165|     22|            if(pad_bits >= bits_per_symbol) {
  ------------------
  |  Branch (165:16): [True: 1, False: 21]
  ------------------
  166|      1|               throw Invalid_Argument(base.name() + " decoding failed, invalid length");
  167|      1|            }
  168|       |
  169|       |            // RFC 4648 3.5: "decoders MAY chose to reject an encoding if the
  170|       |            // pad bits have not been set to zero"
  171|     21|            const uint8_t pad_mask = static_cast<uint8_t>((1U << pad_bits) - 1);
  172|     21|            if(decode_buf[decode_buf_pos - 1] & pad_mask) {
  ------------------
  |  Branch (172:16): [True: 4, False: 17]
  ------------------
  173|      4|               throw Invalid_Argument(base.name() + " decoding failed, nonzero padding bits");
  174|      4|            }
  175|       |
  176|     28|            for(size_t j = decode_buf_pos; j < decoding_bytes_in; ++j) {
  ------------------
  |  Branch (176:44): [True: 11, False: 17]
  ------------------
  177|     11|               decode_buf[j] = 0;
  178|     11|            }
  179|       |
  180|     17|            final_truncate = decoding_bytes_in - decode_buf_pos;
  181|     17|            decode_buf_pos = decoding_bytes_in;
  182|     17|         }
  183|     39|      }
  184|       |
  185|  3.07k|      if(decode_buf_pos == decoding_bytes_in) {
  ------------------
  |  Branch (185:10): [True: 376, False: 2.70k]
  ------------------
  186|    376|         base.decode(out_ptr, decode_buf.data());
  187|       |
  188|    376|         out_ptr += decoding_bytes_out;
  189|    376|         decode_buf_pos = 0;
  190|    376|         input_consumed = i + 1;
  191|    376|      }
  192|  3.07k|   }
  193|       |
  194|    358|   while(input_consumed < input_length && base.lookup_binary_value(input[input_consumed]) == 0x80) {
  ------------------
  |  Branch (194:10): [True: 285, False: 73]
  |  Branch (194:43): [True: 278, False: 7]
  ------------------
  195|    278|      ++input_consumed;
  196|    278|   }
  197|       |
  198|     80|   const size_t written = (out_ptr - output) - base.bytes_to_remove(final_truncate);
  199|       |
  200|     80|   return written;
  201|     92|}
base64.cpp:_ZN5Botan16base_decode_fullINS_12_GLOBAL__N_16Base64EEEmRKT_PhPKcmb:
  204|     92|size_t base_decode_full(const Base& base, uint8_t output[], const char input[], size_t input_length, bool ignore_ws) {
  205|     92|   size_t consumed = 0;
  206|     92|   const size_t written = base_decode(base, output, input, input_length, consumed, true, ignore_ws);
  207|       |
  208|     92|   if(consumed != input_length) {
  ------------------
  |  Branch (208:7): [True: 7, False: 85]
  ------------------
  209|      7|      throw Invalid_Argument(base.name() + " decoding failed, input did not have full bytes");
  210|      7|   }
  211|       |
  212|     85|   return written;
  213|     92|}
base64.cpp:_ZN5Botan18base_decode_to_vecINSt3__16vectorIhNS_16secure_allocatorIhEEEENS_12_GLOBAL__N_16Base64EEET_RKT0_PKcmb:
  216|     92|Vector base_decode_to_vec(const Base& base, const char input[], size_t input_length, bool ignore_ws) {
  217|     92|   const size_t output_length = base.decode_max_output(input_length);
  218|     92|   Vector bin(output_length);
  219|       |
  220|     92|   const size_t written = base_decode_full(base, bin.data(), input, input_length, ignore_ws);
  221|       |
  222|     92|   bin.resize(written);
  223|     92|   return bin;
  224|     92|}

_ZN5Botan5CPUID3hasENS_10CPUFeatureE:
   93|  60.6k|      static bool has(CPUID::Feature feat) { return state().has_bit(feat.as_u32()); }
_ZN5Botan5CPUID5stateEv:
  155|   121k|      static CPUID_Data& state() {
  156|   121k|         static CPUID::CPUID_Data g_cpuid;
  157|   121k|         return g_cpuid;
  158|   121k|      }
_ZNK5Botan5CPUID10CPUID_Data7has_bitEj:
  143|   121k|            bool has_bit(uint32_t bit) const { return (m_processor_features & bit) == bit; }
_ZN5Botan5CPUID3hasENS_10CPUFeatureES1_:
   98|  60.6k|      static bool has(CPUID::Feature feat1, CPUID::Feature feat2) {
   99|  60.6k|         return state().has_bit(feat1.as_u32() | feat2.as_u32());
  100|  60.6k|      }
_ZN5Botan5CPUID6is_setEjNS_10CPUFeatureE:
  126|      4|      static inline bool is_set(uint32_t allowed, CPUID::Feature bit) {
  127|      4|         const uint32_t feat_bit = bit.as_u32();
  128|      4|         return ((allowed & feat_bit) == feat_bit);
  129|      4|      }
cpuid_x86.cpp:_ZN5Botan5CPUID6if_setIZNS0_10CPUID_Data19detect_cpu_featuresEjE16x86_CPUID_1_bitsEEjmT_NS_10CPUFeatureEj:
  116|      6|      static inline uint32_t if_set(uint64_t cpuid, T flag, CPUID::Feature bit, uint32_t allowed) {
  117|      6|         const uint64_t flag64 = static_cast<uint64_t>(flag);
  118|      6|         if((cpuid & flag64) == flag64) {
  ------------------
  |  Branch (118:13): [True: 6, False: 0]
  ------------------
  119|      6|            return (bit.as_u32() & allowed);
  120|      6|         } else {
  121|      0|            return 0;
  122|      0|         }
  123|      6|      }
cpuid_x86.cpp:_ZN5Botan5CPUID6if_setIZNS0_10CPUID_Data19detect_cpu_featuresEjE16x86_CPUID_7_bitsEEjmT_NS_10CPUFeatureEj:
  116|      8|      static inline uint32_t if_set(uint64_t cpuid, T flag, CPUID::Feature bit, uint32_t allowed) {
  117|      8|         const uint64_t flag64 = static_cast<uint64_t>(flag);
  118|      8|         if((cpuid & flag64) == flag64) {
  ------------------
  |  Branch (118:13): [True: 4, False: 4]
  ------------------
  119|      4|            return (bit.as_u32() & allowed);
  120|      4|         } else {
  121|      4|            return 0;
  122|      4|         }
  123|      8|      }
cpuid_x86.cpp:_ZN5Botan5CPUID6if_setIZNS0_10CPUID_Data19detect_cpu_featuresEjE18x86_CPUID_7_1_bitsEEjmT_NS_10CPUFeatureEj:
  116|      3|      static inline uint32_t if_set(uint64_t cpuid, T flag, CPUID::Feature bit, uint32_t allowed) {
  117|      3|         const uint64_t flag64 = static_cast<uint64_t>(flag);
  118|      3|         if((cpuid & flag64) == flag64) {
  ------------------
  |  Branch (118:13): [True: 0, False: 3]
  ------------------
  119|      0|            return (bit.as_u32() & allowed);
  120|      3|         } else {
  121|      3|            return 0;
  122|      3|         }
  123|      3|      }

_ZNK5Botan10CPUFeature6as_u32Ev:
   55|   182k|      uint32_t as_u32() const { return static_cast<uint32_t>(m_bit); }
_ZN5Botan10CPUFeatureC2ENS0_3BitE:
   53|   182k|      CPUFeature(Bit b) : m_bit(b) {}  // NOLINT(*-explicit-conversions)

_ZN5Botan2CT8is_equalIhEENS0_4MaskIT_EENSt3__14spanIKS3_Lm18446744073709551615EEES8_:
  825|  4.29k|constexpr inline CT::Mask<T> is_equal(std::span<const T> x, std::span<const T> y) {
  826|  4.29k|   if(x.size() != y.size()) {
  ------------------
  |  Branch (826:7): [True: 0, False: 4.29k]
  ------------------
  827|      0|      return CT::Mask<T>::cleared();
  828|      0|   }
  829|       |
  830|  4.29k|   return is_equal(x.data(), y.data(), x.size());
  831|  4.29k|}
_ZN5Botan2CT4MaskIhEC2Eh:
  637|  4.29k|      constexpr explicit Mask(T m) : m_mask(m) {}
_ZN5Botan2CT8is_equalIhEENS0_4MaskIT_EEPKS3_S6_m:
  798|  4.29k|constexpr inline CT::Mask<T> is_equal(const T x[], const T y[], size_t len) {
  799|  4.29k|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (799:7): [Folded, False: 4.29k]
  ------------------
  800|      0|      T difference = 0;
  801|       |
  802|      0|      for(size_t i = 0; i != len; ++i) {
  ------------------
  |  Branch (802:25): [True: 0, False: 0]
  ------------------
  803|      0|         difference = difference | (x[i] ^ y[i]);
  804|      0|      }
  805|       |
  806|      0|      return CT::Mask<T>::is_zero(difference);
  807|  4.29k|   } else {
  808|  4.29k|      volatile T difference = 0;
  809|       |
  810|   141k|      for(size_t i = 0; i != len; ++i) {
  ------------------
  |  Branch (810:25): [True: 137k, False: 4.29k]
  ------------------
  811|   137k|         difference = difference | (x[i] ^ y[i]);
  812|   137k|      }
  813|       |
  814|  4.29k|      return CT::Mask<T>::is_zero(difference);
  815|  4.29k|   }
  816|  4.29k|}
_ZN5Botan2CT4MaskIhE7is_zeroEh:
  437|  4.29k|      static constexpr Mask<T> is_zero(T x) { return Mask<T>(ct_is_zero<T>(value_barrier<T>(x))); }
_ZNK5Botan2CT4MaskIhE7as_boolEv:
  614|  4.29k|      constexpr bool as_bool() const { return unpoisoned_value() != 0; }
_ZNK5Botan2CT4MaskIhE16unpoisoned_valueEv:
  598|  4.29k|      constexpr T unpoisoned_value() const {
  599|  4.29k|         T r = value();
  600|  4.29k|         CT::unpoison(r);
  601|  4.29k|         return r;
  602|  4.29k|      }
_ZNK5Botan2CT4MaskIhE5valueEv:
  630|  4.29k|      constexpr T value() const { return value_barrier<T>(m_mask); }
_ZN5Botan2CT8unpoisonITkNSt3__18integralEhEEvRKT_:
  112|  4.29k|constexpr void unpoison(const T& p) {
  113|  4.29k|   unpoison(&p, 1);
  114|  4.29k|}
_ZN5Botan2CT8unpoisonIhEEvPKT_m:
   67|  4.29k|constexpr inline void unpoison(const T* p, size_t n) {
   68|       |#if defined(BOTAN_HAS_VALGRIND)
   69|       |   if(!std::is_constant_evaluated()) {
   70|       |      VALGRIND_MAKE_MEM_DEFINED(p, n * sizeof(T));
   71|       |   }
   72|       |#endif
   73|       |
   74|  4.29k|   BOTAN_UNUSED(p, n);
  ------------------
  |  |  151|  4.29k|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
   75|  4.29k|}
_ZN5Botan2CT4MaskImE7is_zeroEm:
  437|    649|      static constexpr Mask<T> is_zero(T x) { return Mask<T>(ct_is_zero<T>(value_barrier<T>(x))); }
_ZNK5Botan2CT4MaskImE5valueEv:
  630|  1.15k|      constexpr T value() const { return value_barrier<T>(m_mask); }
_ZNK5Botan2CT4MaskImE6selectEmm:
  548|  1.15k|      constexpr T select(T x, T y) const { return choose(value(), x, y); }
_ZN5Botan2CT4MaskImE5is_ltEmm:
  450|    510|      static constexpr Mask<T> is_lt(T x, T y) {
  451|    510|         T u = x ^ ((x ^ y) | ((x - y) ^ x));
  452|    510|         return Mask<T>::expand_top_bit(u);
  453|    510|      }
_ZN5Botan2CT4MaskImE14expand_top_bitEm:
  415|    510|      static constexpr Mask<T> expand_top_bit(T v) { return Mask<T>(ct_expand_top_bit<T>(v)); }
_ZN5Botan2CT4MaskImEC2Em:
  637|  1.15k|      constexpr explicit Mask(T m) : m_mask(m) {}
_ZN5Botan2CT8unpoisonITkNSt3__18integralEmEEvRKT_:
  112|  9.65k|constexpr void unpoison(const T& p) {
  113|  9.65k|   unpoison(&p, 1);
  114|  9.65k|}
_ZN5Botan2CT4MaskImE8is_equalEmm:
  442|    510|      static constexpr Mask<T> is_equal(T x, T y) {
  443|    510|         const T diff = value_barrier(x) ^ value_barrier(y);
  444|    510|         return Mask<T>::is_zero(diff);
  445|    510|      }
_ZN5Botan2CT8unpoisonImEEvPKT_m:
   67|  14.8k|constexpr inline void unpoison(const T* p, size_t n) {
   68|       |#if defined(BOTAN_HAS_VALGRIND)
   69|       |   if(!std::is_constant_evaluated()) {
   70|       |      VALGRIND_MAKE_MEM_DEFINED(p, n * sizeof(T));
   71|       |   }
   72|       |#endif
   73|       |
   74|  14.8k|   BOTAN_UNUSED(p, n);
  ------------------
  |  |  151|  14.8k|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
   75|  14.8k|}

_ZN5Botan3fmtIJmmEEENSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EEDpRKT_:
   53|    508|std::string fmt(std::string_view format, const T&... args) {
   54|    508|   std::ostringstream oss;
   55|    508|   oss.imbue(std::locale::classic());
   56|    508|   fmt_detail::do_fmt(oss, format, args...);
   57|    508|   return oss.str();
   58|    508|}
_ZN5Botan10fmt_detail6do_fmtImJmEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|    508|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|    508|   size_t i = 0;
   27|       |
   28|  5.53k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 5.53k, False: 0]
  ------------------
   29|  5.53k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 508, False: 5.02k]
  |  Branch (29:30): [True: 508, False: 0]
  |  Branch (29:59): [True: 508, False: 0]
  ------------------
   30|    508|         oss << val;
   31|    508|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  5.02k|      } else {
   33|  5.02k|         oss << format[i];
   34|  5.02k|      }
   35|       |
   36|  5.02k|      i += 1;
   37|  5.02k|   }
   38|    508|}
_ZN5Botan10fmt_detail6do_fmtImJEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|    508|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|    508|   size_t i = 0;
   27|       |
   28|  12.3k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 12.3k, False: 0]
  ------------------
   29|  12.3k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 508, False: 11.7k]
  |  Branch (29:30): [True: 508, False: 0]
  |  Branch (29:59): [True: 508, False: 0]
  ------------------
   30|    508|         oss << val;
   31|    508|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  11.7k|      } else {
   33|  11.7k|         oss << format[i];
   34|  11.7k|      }
   35|       |
   36|  11.7k|      i += 1;
   37|  11.7k|   }
   38|    508|}
_ZN5Botan10fmt_detail6do_fmtERNSt3__119basic_ostringstreamIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EE:
   20|  12.4k|inline void do_fmt(std::ostringstream& oss, std::string_view format) {
   21|  12.4k|   oss << format;
   22|  12.4k|}
_ZN5Botan3fmtIJNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEEEES7_NS1_17basic_string_viewIcS4_EEDpRKT_:
   53|  1.56k|std::string fmt(std::string_view format, const T&... args) {
   54|  1.56k|   std::ostringstream oss;
   55|  1.56k|   oss.imbue(std::locale::classic());
   56|  1.56k|   fmt_detail::do_fmt(oss, format, args...);
   57|  1.56k|   return oss.str();
   58|  1.56k|}
_ZN5Botan10fmt_detail6do_fmtINSt3__112basic_stringIcNS2_11char_traitsIcEENS2_9allocatorIcEEEEJEEEvRNS2_19basic_ostringstreamIcS5_S7_EENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|  1.56k|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|  1.56k|   size_t i = 0;
   27|       |
   28|  80.7k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 80.7k, False: 0]
  ------------------
   29|  80.7k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 1.56k, False: 79.1k]
  |  Branch (29:30): [True: 1.56k, False: 0]
  |  Branch (29:59): [True: 1.56k, False: 0]
  ------------------
   30|  1.56k|         oss << val;
   31|  1.56k|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  79.1k|      } else {
   33|  79.1k|         oss << format[i];
   34|  79.1k|      }
   35|       |
   36|  79.1k|      i += 1;
   37|  79.1k|   }
   38|  1.56k|}
_ZN5Botan3fmtIJPKcNSt3__117basic_string_viewIcNS3_11char_traitsIcEEEEEEENS3_12basic_stringIcS6_NS3_9allocatorIcEEEES7_DpRKT_:
   53|    575|std::string fmt(std::string_view format, const T&... args) {
   54|    575|   std::ostringstream oss;
   55|    575|   oss.imbue(std::locale::classic());
   56|    575|   fmt_detail::do_fmt(oss, format, args...);
   57|    575|   return oss.str();
   58|    575|}
_ZN5Botan10fmt_detail6do_fmtIPKcJNSt3__117basic_string_viewIcNS4_11char_traitsIcEEEEEEEvRNS4_19basic_ostringstreamIcS7_NS4_9allocatorIcEEEES8_RKT_DpRKT0_:
   25|    575|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|    575|   size_t i = 0;
   27|       |
   28|  5.16k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 5.16k, False: 0]
  ------------------
   29|  5.16k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 575, False: 4.59k]
  |  Branch (29:30): [True: 575, False: 0]
  |  Branch (29:59): [True: 575, False: 0]
  ------------------
   30|    575|         oss << val;
   31|    575|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  4.59k|      } else {
   33|  4.59k|         oss << format[i];
   34|  4.59k|      }
   35|       |
   36|  4.59k|      i += 1;
   37|  4.59k|   }
   38|    575|}
_ZN5Botan10fmt_detail6do_fmtINSt3__117basic_string_viewIcNS2_11char_traitsIcEEEEJEEEvRNS2_19basic_ostringstreamIcS5_NS2_9allocatorIcEEEES6_RKT_DpRKT0_:
   25|  5.87k|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|  5.87k|   size_t i = 0;
   27|       |
   28|  58.1k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 58.1k, False: 0]
  ------------------
   29|  58.1k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 5.87k, False: 52.2k]
  |  Branch (29:30): [True: 5.87k, False: 0]
  |  Branch (29:59): [True: 5.87k, False: 0]
  ------------------
   30|  5.87k|         oss << val;
   31|  5.87k|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  52.2k|      } else {
   33|  52.2k|         oss << format[i];
   34|  52.2k|      }
   35|       |
   36|  52.2k|      i += 1;
   37|  52.2k|   }
   38|  5.87k|}
_ZN5Botan3fmtIJNSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEEEENS1_12basic_stringIcS4_NS1_9allocatorIcEEEES5_DpRKT_:
   53|  5.29k|std::string fmt(std::string_view format, const T&... args) {
   54|  5.29k|   std::ostringstream oss;
   55|  5.29k|   oss.imbue(std::locale::classic());
   56|  5.29k|   fmt_detail::do_fmt(oss, format, args...);
   57|  5.29k|   return oss.str();
   58|  5.29k|}
_ZN5Botan3fmtIJPKcS2_S2_EEENSt3__112basic_stringIcNS3_11char_traitsIcEENS3_9allocatorIcEEEENS3_17basic_string_viewIcS6_EEDpRKT_:
   53|     16|std::string fmt(std::string_view format, const T&... args) {
   54|     16|   std::ostringstream oss;
   55|     16|   oss.imbue(std::locale::classic());
   56|     16|   fmt_detail::do_fmt(oss, format, args...);
   57|     16|   return oss.str();
   58|     16|}
_ZN5Botan10fmt_detail6do_fmtIPKcJS3_S3_EEEvRNSt3__119basic_ostringstreamIcNS4_11char_traitsIcEENS4_9allocatorIcEEEENS4_17basic_string_viewIcS7_EERKT_DpRKT0_:
   25|     16|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|     16|   size_t i = 0;
   27|       |
   28|     16|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 16, False: 0]
  ------------------
   29|     16|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 16, False: 0]
  |  Branch (29:30): [True: 16, False: 0]
  |  Branch (29:59): [True: 16, False: 0]
  ------------------
   30|     16|         oss << val;
   31|     16|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|     16|      } else {
   33|      0|         oss << format[i];
   34|      0|      }
   35|       |
   36|      0|      i += 1;
   37|      0|   }
   38|     16|}
_ZN5Botan10fmt_detail6do_fmtIPKcJS3_EEEvRNSt3__119basic_ostringstreamIcNS4_11char_traitsIcEENS4_9allocatorIcEEEENS4_17basic_string_viewIcS7_EERKT_DpRKT0_:
   25|     16|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|     16|   size_t i = 0;
   27|       |
   28|     80|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 80, False: 0]
  ------------------
   29|     80|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 16, False: 64]
  |  Branch (29:30): [True: 16, False: 0]
  |  Branch (29:59): [True: 16, False: 0]
  ------------------
   30|     16|         oss << val;
   31|     16|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|     64|      } else {
   33|     64|         oss << format[i];
   34|     64|      }
   35|       |
   36|     64|      i += 1;
   37|     64|   }
   38|     16|}
_ZN5Botan10fmt_detail6do_fmtIPKcJEEEvRNSt3__119basic_ostringstreamIcNS4_11char_traitsIcEENS4_9allocatorIcEEEENS4_17basic_string_viewIcS7_EERKT_DpRKT0_:
   25|  4.25k|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|  4.25k|   size_t i = 0;
   27|       |
   28|  60.1k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 60.1k, False: 0]
  ------------------
   29|  60.1k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 4.25k, False: 55.8k]
  |  Branch (29:30): [True: 4.25k, False: 0]
  |  Branch (29:59): [True: 4.25k, False: 0]
  ------------------
   30|  4.25k|         oss << val;
   31|  4.25k|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  55.8k|      } else {
   33|  55.8k|         oss << format[i];
   34|  55.8k|      }
   35|       |
   36|  55.8k|      i += 1;
   37|  55.8k|   }
   38|  4.25k|}
_ZN5Botan3fmtIJNSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEPKcEEENS1_12basic_stringIcS4_NS1_9allocatorIcEEEES5_DpRKT_:
   53|  4.18k|std::string fmt(std::string_view format, const T&... args) {
   54|  4.18k|   std::ostringstream oss;
   55|  4.18k|   oss.imbue(std::locale::classic());
   56|  4.18k|   fmt_detail::do_fmt(oss, format, args...);
   57|  4.18k|   return oss.str();
   58|  4.18k|}
_ZN5Botan10fmt_detail6do_fmtINSt3__117basic_string_viewIcNS2_11char_traitsIcEEEEJPKcEEEvRNS2_19basic_ostringstreamIcS5_NS2_9allocatorIcEEEES6_RKT_DpRKT0_:
   25|  4.18k|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|  4.18k|   size_t i = 0;
   27|       |
   28|  4.18k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 4.18k, False: 0]
  ------------------
   29|  4.18k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 4.18k, False: 0]
  |  Branch (29:30): [True: 4.18k, False: 0]
  |  Branch (29:59): [True: 4.18k, False: 0]
  ------------------
   30|  4.18k|         oss << val;
   31|  4.18k|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  4.18k|      } else {
   33|      0|         oss << format[i];
   34|      0|      }
   35|       |
   36|      0|      i += 1;
   37|      0|   }
   38|  4.18k|}
_ZN5Botan3fmtIJNSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEjEEENS1_12basic_stringIcS4_NS1_9allocatorIcEEEES5_DpRKT_:
   53|     59|std::string fmt(std::string_view format, const T&... args) {
   54|     59|   std::ostringstream oss;
   55|     59|   oss.imbue(std::locale::classic());
   56|     59|   fmt_detail::do_fmt(oss, format, args...);
   57|     59|   return oss.str();
   58|     59|}
_ZN5Botan10fmt_detail6do_fmtINSt3__117basic_string_viewIcNS2_11char_traitsIcEEEEJjEEEvRNS2_19basic_ostringstreamIcS5_NS2_9allocatorIcEEEES6_RKT_DpRKT0_:
   25|     59|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|     59|   size_t i = 0;
   27|       |
   28|     59|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 59, False: 0]
  ------------------
   29|     59|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 59, False: 0]
  |  Branch (29:30): [True: 59, False: 0]
  |  Branch (29:59): [True: 59, False: 0]
  ------------------
   30|     59|         oss << val;
   31|     59|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|     59|      } else {
   33|      0|         oss << format[i];
   34|      0|      }
   35|       |
   36|      0|      i += 1;
   37|      0|   }
   38|     59|}
_ZN5Botan10fmt_detail6do_fmtIjJEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|    210|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|    210|   size_t i = 0;
   27|       |
   28|    785|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 785, False: 0]
  ------------------
   29|    785|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 210, False: 575]
  |  Branch (29:30): [True: 210, False: 0]
  |  Branch (29:59): [True: 210, False: 0]
  ------------------
   30|    210|         oss << val;
   31|    210|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|    575|      } else {
   33|    575|         oss << format[i];
   34|    575|      }
   35|       |
   36|    575|      i += 1;
   37|    575|   }
   38|    210|}
_ZN5Botan3fmtIJjjEEENSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EEDpRKT_:
   53|    141|std::string fmt(std::string_view format, const T&... args) {
   54|    141|   std::ostringstream oss;
   55|    141|   oss.imbue(std::locale::classic());
   56|    141|   fmt_detail::do_fmt(oss, format, args...);
   57|    141|   return oss.str();
   58|    141|}
_ZN5Botan10fmt_detail6do_fmtIjJjEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|    141|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|    141|   size_t i = 0;
   27|       |
   28|  4.19k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 4.19k, False: 0]
  ------------------
   29|  4.19k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 141, False: 4.04k]
  |  Branch (29:30): [True: 141, False: 0]
  |  Branch (29:59): [True: 141, False: 0]
  ------------------
   30|    141|         oss << val;
   31|    141|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  4.04k|      } else {
   33|  4.04k|         oss << format[i];
   34|  4.04k|      }
   35|       |
   36|  4.04k|      i += 1;
   37|  4.04k|   }
   38|    141|}
_ZN5Botan3fmtIJtttEEENSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EEDpRKT_:
   53|      8|std::string fmt(std::string_view format, const T&... args) {
   54|      8|   std::ostringstream oss;
   55|      8|   oss.imbue(std::locale::classic());
   56|      8|   fmt_detail::do_fmt(oss, format, args...);
   57|      8|   return oss.str();
   58|      8|}
_ZN5Botan10fmt_detail6do_fmtItJttEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|      8|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|      8|   size_t i = 0;
   27|       |
   28|    128|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 128, False: 0]
  ------------------
   29|    128|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 8, False: 120]
  |  Branch (29:30): [True: 8, False: 0]
  |  Branch (29:59): [True: 8, False: 0]
  ------------------
   30|      8|         oss << val;
   31|      8|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|    120|      } else {
   33|    120|         oss << format[i];
   34|    120|      }
   35|       |
   36|    120|      i += 1;
   37|    120|   }
   38|      8|}
_ZN5Botan10fmt_detail6do_fmtItJtEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|      8|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|      8|   size_t i = 0;
   27|       |
   28|    152|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 152, False: 0]
  ------------------
   29|    152|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 8, False: 144]
  |  Branch (29:30): [True: 8, False: 0]
  |  Branch (29:59): [True: 8, False: 0]
  ------------------
   30|      8|         oss << val;
   31|      8|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|    144|      } else {
   33|    144|         oss << format[i];
   34|    144|      }
   35|       |
   36|    144|      i += 1;
   37|    144|   }
   38|      8|}
_ZN5Botan10fmt_detail6do_fmtItJEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|      8|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|      8|   size_t i = 0;
   27|       |
   28|     40|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 40, False: 0]
  ------------------
   29|     40|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 8, False: 32]
  |  Branch (29:30): [True: 8, False: 0]
  |  Branch (29:59): [True: 8, False: 0]
  ------------------
   30|      8|         oss << val;
   31|      8|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|     32|      } else {
   33|     32|         oss << format[i];
   34|     32|      }
   35|       |
   36|     32|      i += 1;
   37|     32|   }
   38|      8|}
_ZN5Botan3fmtIJjEEENSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EEDpRKT_:
   53|     10|std::string fmt(std::string_view format, const T&... args) {
   54|     10|   std::ostringstream oss;
   55|     10|   oss.imbue(std::locale::classic());
   56|     10|   fmt_detail::do_fmt(oss, format, args...);
   57|     10|   return oss.str();
   58|     10|}
_ZN5Botan3fmtIJPKcEEENSt3__112basic_stringIcNS3_11char_traitsIcEENS3_9allocatorIcEEEENS3_17basic_string_viewIcS6_EEDpRKT_:
   53|     51|std::string fmt(std::string_view format, const T&... args) {
   54|     51|   std::ostringstream oss;
   55|     51|   oss.imbue(std::locale::classic());
   56|     51|   fmt_detail::do_fmt(oss, format, args...);
   57|     51|   return oss.str();
   58|     51|}

_ZN5Botan11checked_mulITkNSt3__117unsigned_integralEmEENS1_8optionalIT_EES3_S3_:
   46|  67.6k|constexpr inline std::optional<T> checked_mul(T a, T b) {
   47|       |   // Multiplication by 1U is a hack to work around C's insane
   48|       |   // integer promotion rules.
   49|       |   // https://stackoverflow.com/questions/24795651
   50|  67.6k|   const T r = (1U * a) * b;
   51|       |   // If a == 0 then the multiply certainly did not overflow
   52|       |   // Otherwise r / a == b unless overflow occurred
   53|  67.6k|   if(a != 0 && r / a != b) {
  ------------------
  |  Branch (53:7): [True: 67.6k, False: 0]
  |  Branch (53:17): [True: 0, False: 67.6k]
  ------------------
   54|      0|      return {};
   55|      0|   }
   56|  67.6k|   return r;
   57|  67.6k|}
_ZN5Botan11checked_addITkNSt3__117unsigned_integralEjEENS1_8optionalIT_EES3_S3_:
   19|  2.26k|constexpr inline std::optional<T> checked_add(T a, T b) {
   20|  2.26k|   const T r = a + b;
   21|  2.26k|   if(r < a || r < b) {
  ------------------
  |  Branch (21:7): [True: 0, False: 2.26k]
  |  Branch (21:16): [True: 0, False: 2.26k]
  ------------------
   22|      0|      return {};
   23|      0|   }
   24|  2.26k|   return r;
   25|  2.26k|}
_ZN5Botan11checked_addITkNSt3__117unsigned_integralEmTpTkNS1_17unsigned_integralEJmmEQ10all_same_vIT_DpT0_EEENS1_8optionalIS2_EES2_S2_S4_:
   37|  1.87k|constexpr inline std::optional<T> checked_add(T a, T b, Ts... rest) {
   38|  1.87k|   if(auto r = checked_add(a, b)) {
  ------------------
  |  Branch (38:12): [True: 1.87k, False: 0]
  ------------------
   39|  1.87k|      return checked_add(r.value(), rest...);
   40|  1.87k|   } else {
   41|      0|      return {};
   42|      0|   }
   43|  1.87k|}
_ZN5Botan11checked_addITkNSt3__117unsigned_integralEmEENS1_8optionalIT_EES3_S3_:
   19|  5.61k|constexpr inline std::optional<T> checked_add(T a, T b) {
   20|  5.61k|   const T r = a + b;
   21|  5.61k|   if(r < a || r < b) {
  ------------------
  |  Branch (21:7): [True: 0, False: 5.61k]
  |  Branch (21:16): [True: 0, False: 5.61k]
  ------------------
   22|      0|      return {};
   23|      0|   }
   24|  5.61k|   return r;
   25|  5.61k|}
_ZN5Botan11checked_addITkNSt3__117unsigned_integralEmTpTkNS1_17unsigned_integralEJmEQ10all_same_vIT_DpT0_EEENS1_8optionalIS2_EES2_S2_S4_:
   37|  1.87k|constexpr inline std::optional<T> checked_add(T a, T b, Ts... rest) {
   38|  1.87k|   if(auto r = checked_add(a, b)) {
  ------------------
  |  Branch (38:12): [True: 1.87k, False: 0]
  ------------------
   39|  1.87k|      return checked_add(r.value(), rest...);
   40|  1.87k|   } else {
   41|      0|      return {};
   42|      0|   }
   43|  1.87k|}
_ZN5Botan7swar_ltITkNSt3__117unsigned_integralEtEET_S2_S2_:
  121|  68.6k|constexpr T swar_lt(T a, T b) {
  122|       |   // The constant 0x808080... as a T
  123|  68.6k|   constexpr T hi1 = (static_cast<T>(-1) / 255) << 7;
  124|       |   // The constant 0x7F7F7F... as a T
  125|  68.6k|   constexpr T lo7 = static_cast<T>(~hi1);
  126|  68.6k|   T r = (lo7 - a + b) & hi1;
  127|       |   // Currently the mask is 80 if lt, otherwise 00. Convert to FF/00
  128|  68.6k|   return (r << 1) - (r >> 7);
  129|  68.6k|}
_ZN5Botan12mul_or_throwITkNSt3__117unsigned_integralEmEET_S2_S2_NS1_17basic_string_viewIcNS1_11char_traitsIcEEEE:
   81|  2.64k|constexpr T mul_or_throw(T a, T b, std::string_view msg) {
   82|  2.64k|   if(auto r = checked_mul(a, b)) {
  ------------------
  |  Branch (82:12): [True: 2.64k, False: 0]
  ------------------
   83|  2.64k|      return r.value();
   84|  2.64k|   } else {
   85|      0|      throw Invalid_Argument(msg);
   86|      0|   }
   87|  2.64k|}
_ZN5Botan13swar_in_rangeITkNSt3__117unsigned_integralEmEET_S2_S2_S2_:
  144|  3.37k|constexpr T swar_in_range(T v, T lower, T upper) {
  145|       |   // The constant 0x808080... as a T
  146|  3.37k|   constexpr T hi1 = (static_cast<T>(-1) / 255) << 7;
  147|       |   // The constant 0x7F7F7F... as a T
  148|  3.37k|   constexpr T lo7 = ~hi1;
  149|       |
  150|  3.37k|   const T sub = ((v | hi1) - (lower & lo7)) ^ ((v ^ (~lower)) & hi1);
  151|  3.37k|   const T a_lo = sub & lo7;
  152|  3.37k|   const T a_hi = sub & hi1;
  153|  3.37k|   return (lo7 - a_lo + upper) & hi1 & ~a_hi;
  154|  3.37k|}

_ZN5Botan11make_uint16Ehh:
   92|   154k|inline constexpr uint16_t make_uint16(uint8_t i0, uint8_t i1) {
   93|   154k|   return static_cast<uint16_t>((static_cast<uint16_t>(i0) << 8) | i1);
   94|   154k|}
_ZN5Botan8get_byteILm0EtEEhT0_QltT_stS1_:
   81|  68.6k|{
   82|  68.6k|   const size_t shift = ((~B) & (sizeof(T) - 1)) << 3;
   83|  68.6k|   return static_cast<uint8_t>((input >> shift) & 0xFF);
   84|  68.6k|}
_ZN5Botan8get_byteILm1EtEEhT0_QltT_stS1_:
   81|  68.6k|{
   82|  68.6k|   const size_t shift = ((~B) & (sizeof(T) - 1)) << 3;
   83|  68.6k|   return static_cast<uint8_t>((input >> shift) & 0xFF);
   84|  68.6k|}
_ZN5Botan11make_uint32Ehhhh:
  104|  42.2k|inline constexpr uint32_t make_uint32(uint8_t i0, uint8_t i1, uint8_t i2, uint8_t i3) {
  105|  42.2k|   return ((static_cast<uint32_t>(i0) << 24) | (static_cast<uint32_t>(i1) << 16) | (static_cast<uint32_t>(i2) << 8) |
  106|  42.2k|           (static_cast<uint32_t>(i3)));
  107|  42.2k|}
_ZN5Botan7load_beIhJPKhRmEEEDaDpOT0_:
  504|  2.79M|inline constexpr auto load_be(ParamTs&&... params) {
  505|  2.79M|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|  2.79M|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEhEET0_PKhm:
  454|  2.79M|inline constexpr OutT load_any(const uint8_t in[], size_t off) {
  455|       |   // asserts that *in points to enough bytes to read at offset off
  456|  2.79M|   constexpr size_t out_size = sizeof(OutT);
  457|  2.79M|   return load_any<endianness, OutT>(std::span<const uint8_t, out_size>(in + off * out_size, out_size));
  458|  2.79M|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEhTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm1EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|  2.79M|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|  2.79M|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|  2.79M|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|  2.79M|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  2.79M|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|  2.79M|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  2.79M|      } else {
  289|  2.79M|         const std::span in{in_range};
  290|  2.79M|         if constexpr(sizeof(OutT) == 1) {
  291|  2.79M|            return static_cast<OutT>(in[0]);
  292|  2.79M|         } else if constexpr(endianness == std::endian::native) {
  293|  2.79M|            return typecast_copy<OutT>(in);
  294|  2.79M|         } else {
  295|  2.79M|            static_assert(opposite(endianness) == std::endian::native);
  296|  2.79M|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  2.79M|         }
  298|  2.79M|      }
  299|  2.79M|   }());
  300|  2.79M|}
_ZN5Botan6detail24wrap_strong_type_or_enumITkNS0_20unsigned_integralishEhTkNSt3__117unsigned_integralEhEEDaT0_:
  200|  2.79M|constexpr auto wrap_strong_type_or_enum(T t) {
  201|       |   if constexpr(std::is_enum_v<OutT>) {
  202|       |      return static_cast<OutT>(t);
  203|  2.79M|   } else {
  204|  2.79M|      return Botan::wrap_strong_type<OutT>(t);
  205|  2.79M|   }
  206|  2.79M|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEhTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm1EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|  2.79M|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  2.79M|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 2.79M]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  2.79M|      } else {
  289|  2.79M|         const std::span in{in_range};
  290|  2.79M|         if constexpr(sizeof(OutT) == 1) {
  291|  2.79M|            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|       |         } else {
  295|       |            static_assert(opposite(endianness) == std::endian::native);
  296|       |            return reverse_bytes(typecast_copy<OutT>(in));
  297|       |         }
  298|  2.79M|      }
  299|  2.79M|   }());
_ZN5Botan12get_byte_varImEEhmT_:
   69|  4.95k|inline constexpr uint8_t get_byte_var(size_t byte_num, T input) {
   70|  4.95k|   return static_cast<uint8_t>(input >> (((~byte_num) & (sizeof(T) - 1)) << 3));
   71|  4.95k|}
_ZN5Botan6detail9store_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEjTkNS_6ranges23contiguous_output_rangeIhEENS2_4spanIhLm4EEEQnt15custom_storableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEEvS9_OT1_:
  525|   321k|inline constexpr void store_any(WrappedInT wrapped_in, OutR&& out_range) {
  526|   321k|   const auto in = detail::unwrap_strong_type_or_enum(wrapped_in);
  527|   321k|   using InT = decltype(in);
  528|   321k|   ranges::assert_exact_byte_length<sizeof(in)>(out_range);
  529|   321k|   const std::span out{out_range};
  530|       |
  531|       |   // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  532|       |   // internally to copy ranges on a byte-by-byte basis, which is not allowed
  533|       |   // in a `constexpr` context.
  534|   321k|   if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (534:7): [Folded, False: 321k]
  ------------------
  535|      0|      return fallback_store_any<endianness, InT>(in, std::forward<OutR>(out_range));
  536|   321k|   } else {
  537|       |      if constexpr(sizeof(InT) == 1) {
  538|       |         out[0] = static_cast<uint8_t>(in);
  539|       |      } else if constexpr(endianness == std::endian::native) {
  540|       |         typecast_copy(out, in);
  541|   321k|      } else {
  542|   321k|         static_assert(opposite(endianness) == std::endian::native);
  543|   321k|         typecast_copy(out, reverse_bytes(in));
  544|   321k|      }
  545|   321k|   }
  546|   321k|}
_ZN5Botan6detail26unwrap_strong_type_or_enumITkNS0_20unsigned_integralishEjEEDaT_:
  190|   321k|constexpr auto unwrap_strong_type_or_enum(InT t) {
  191|       |   if constexpr(std::is_enum_v<InT>) {
  192|       |      // TODO: C++23: use std::to_underlying(in) instead
  193|       |      return static_cast<std::underlying_type_t<InT>>(t);
  194|   321k|   } else {
  195|   321k|      return Botan::unwrap_strong_type(t);
  196|   321k|   }
  197|   321k|}
_ZN5Botan7load_beItJPKhRmEEEDaDpOT0_:
  504|  43.2k|inline constexpr auto load_be(ParamTs&&... params) {
  505|  43.2k|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|  43.2k|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEtEET0_PKhm:
  454|  43.2k|inline constexpr OutT load_any(const uint8_t in[], size_t off) {
  455|       |   // asserts that *in points to enough bytes to read at offset off
  456|  43.2k|   constexpr size_t out_size = sizeof(OutT);
  457|  43.2k|   return load_any<endianness, OutT>(std::span<const uint8_t, out_size>(in + off * out_size, out_size));
  458|  43.2k|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEtTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm2EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|  43.2k|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|  43.2k|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|  43.2k|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|  43.2k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  43.2k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|  43.2k|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  43.2k|      } else {
  289|  43.2k|         const std::span in{in_range};
  290|  43.2k|         if constexpr(sizeof(OutT) == 1) {
  291|  43.2k|            return static_cast<OutT>(in[0]);
  292|  43.2k|         } else if constexpr(endianness == std::endian::native) {
  293|  43.2k|            return typecast_copy<OutT>(in);
  294|  43.2k|         } else {
  295|  43.2k|            static_assert(opposite(endianness) == std::endian::native);
  296|  43.2k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  43.2k|         }
  298|  43.2k|      }
  299|  43.2k|   }());
  300|  43.2k|}
_ZN5Botan6detail24wrap_strong_type_or_enumITkNS0_20unsigned_integralishEtTkNSt3__117unsigned_integralEtEEDaT0_:
  200|  43.2k|constexpr auto wrap_strong_type_or_enum(T t) {
  201|       |   if constexpr(std::is_enum_v<OutT>) {
  202|       |      return static_cast<OutT>(t);
  203|  43.2k|   } else {
  204|  43.2k|      return Botan::wrap_strong_type<OutT>(t);
  205|  43.2k|   }
  206|  43.2k|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEtTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm2EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|  43.2k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  43.2k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 43.2k]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  43.2k|      } else {
  289|  43.2k|         const std::span in{in_range};
  290|       |         if constexpr(sizeof(OutT) == 1) {
  291|       |            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|  43.2k|         } else {
  295|  43.2k|            static_assert(opposite(endianness) == std::endian::native);
  296|  43.2k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  43.2k|         }
  298|  43.2k|      }
  299|  43.2k|   }());
_ZN5Botan6detail26unwrap_strong_type_or_enumITkNS0_20unsigned_integralishEmEEDaT_:
  190|  42.3k|constexpr auto unwrap_strong_type_or_enum(InT t) {
  191|       |   if constexpr(std::is_enum_v<InT>) {
  192|       |      // TODO: C++23: use std::to_underlying(in) instead
  193|       |      return static_cast<std::underlying_type_t<InT>>(t);
  194|  42.3k|   } else {
  195|  42.3k|      return Botan::unwrap_strong_type(t);
  196|  42.3k|   }
  197|  42.3k|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|    252|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|    252|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|    252|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|    252|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|    252|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|    252|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|    252|      } else {
  289|    252|         const std::span in{in_range};
  290|    252|         if constexpr(sizeof(OutT) == 1) {
  291|    252|            return static_cast<OutT>(in[0]);
  292|    252|         } else if constexpr(endianness == std::endian::native) {
  293|    252|            return typecast_copy<OutT>(in);
  294|    252|         } else {
  295|    252|            static_assert(opposite(endianness) == std::endian::native);
  296|    252|            return reverse_bytes(typecast_copy<OutT>(in));
  297|    252|         }
  298|    252|      }
  299|    252|   }());
  300|    252|}
_ZN5Botan6detail24wrap_strong_type_or_enumITkNS0_20unsigned_integralishEmTkNSt3__117unsigned_integralEmEEDaT0_:
  200|  3.34k|constexpr auto wrap_strong_type_or_enum(T t) {
  201|       |   if constexpr(std::is_enum_v<OutT>) {
  202|       |      return static_cast<OutT>(t);
  203|  3.34k|   } else {
  204|  3.34k|      return Botan::wrap_strong_type<OutT>(t);
  205|  3.34k|   }
  206|  3.34k|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|    252|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|    252|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 252]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|    252|      } else {
  289|    252|         const std::span in{in_range};
  290|       |         if constexpr(sizeof(OutT) == 1) {
  291|       |            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|    252|         } else {
  295|    252|            static_assert(opposite(endianness) == std::endian::native);
  296|    252|            return reverse_bytes(typecast_copy<OutT>(in));
  297|    252|         }
  298|    252|      }
  299|    252|   }());
_ZN5Botan8get_byteILm0EmEEhT0_QltT_stS1_:
   81|    258|{
   82|    258|   const size_t shift = ((~B) & (sizeof(T) - 1)) << 3;
   83|    258|   return static_cast<uint8_t>((input >> shift) & 0xFF);
   84|    258|}
_ZN5Botan6detail9store_anyILNSt3__16endianE64206EjTkNS_6ranges23contiguous_output_rangeIhEENS2_4spanIhLm4EEETpTkNS0_20unsigned_integralishEJjEQaagtsZT2_Li0Eooaasr3stdE7same_asINS0_10AutoDetectET0_E10all_same_vIDpT2_Eaa20unsigned_integralishIS9_E10all_same_vIS9_SB_EEEvOT1_SB_:
  582|   321k|inline constexpr void store_any(OutR&& out /* NOLINT(*-std-forward) */, Ts... ins) {
  583|   321k|   ranges::assert_exact_byte_length<(sizeof(Ts) + ...)>(out);
  584|   321k|   auto store_one = [off = 0]<typename T>(auto o, T i) mutable {
  585|   321k|      store_any<endianness, T>(i, o.subspan(off).template first<sizeof(T)>());
  586|   321k|      off += sizeof(T);
  587|   321k|   };
  588|       |
  589|   321k|   (store_one(std::span{out}, ins), ...);
  590|   321k|}
_ZZN5Botan6detail9store_anyILNSt3__16endianE64206EjTkNS_6ranges23contiguous_output_rangeIhEENS2_4spanIhLm4EEETpTkNS0_20unsigned_integralishEJjEQaagtsZT2_Li0Eooaasr3stdE7same_asINS0_10AutoDetectET0_E10all_same_vIDpT2_Eaa20unsigned_integralishIS9_E10all_same_vIS9_SB_EEEvOT1_SB_ENUlTyS9_T_E_clIjS7_EEDaS9_SE_:
  584|   321k|   auto store_one = [off = 0]<typename T>(auto o, T i) mutable {
  585|   321k|      store_any<endianness, T>(i, o.subspan(off).template first<sizeof(T)>());
  586|   321k|      off += sizeof(T);
  587|   321k|   };
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEjEET0_PKhm:
  454|    182|inline constexpr OutT load_any(const uint8_t in[], size_t off) {
  455|       |   // asserts that *in points to enough bytes to read at offset off
  456|    182|   constexpr size_t out_size = sizeof(OutT);
  457|    182|   return load_any<endianness, OutT>(std::span<const uint8_t, out_size>(in + off * out_size, out_size));
  458|    182|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEjTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm4EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|    182|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|    182|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|    182|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|    182|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|    182|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|    182|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|    182|      } else {
  289|    182|         const std::span in{in_range};
  290|    182|         if constexpr(sizeof(OutT) == 1) {
  291|    182|            return static_cast<OutT>(in[0]);
  292|    182|         } else if constexpr(endianness == std::endian::native) {
  293|    182|            return typecast_copy<OutT>(in);
  294|    182|         } else {
  295|    182|            static_assert(opposite(endianness) == std::endian::native);
  296|    182|            return reverse_bytes(typecast_copy<OutT>(in));
  297|    182|         }
  298|    182|      }
  299|    182|   }());
  300|    182|}
_ZN5Botan6detail24wrap_strong_type_or_enumITkNS0_20unsigned_integralishEjTkNSt3__117unsigned_integralEjEEDaT0_:
  200|    182|constexpr auto wrap_strong_type_or_enum(T t) {
  201|       |   if constexpr(std::is_enum_v<OutT>) {
  202|       |      return static_cast<OutT>(t);
  203|    182|   } else {
  204|    182|      return Botan::wrap_strong_type<OutT>(t);
  205|    182|   }
  206|    182|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEjTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm4EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|    182|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|    182|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 182]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|    182|      } else {
  289|    182|         const std::span in{in_range};
  290|       |         if constexpr(sizeof(OutT) == 1) {
  291|       |            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|    182|         } else {
  295|    182|            static_assert(opposite(endianness) == std::endian::native);
  296|    182|            return reverse_bytes(typecast_copy<OutT>(in));
  297|    182|         }
  298|    182|      }
  299|    182|   }());
_ZN5Botan8store_leINS_6detail10AutoDetectEJmEEEDaDpOT0_:
  736|  2.23k|inline constexpr auto store_le(ParamTs&&... params) {
  737|  2.23k|   return detail::store_any<std::endian::little, ModifierT>(std::forward<ParamTs>(params)...);
  738|  2.23k|}
_ZN5Botan6detail9store_anyILNSt3__16endianE57005ENS0_10AutoDetectETpTkNS0_20unsigned_integralishEJmEQ10all_same_vIDpT1_EEEDaS6_:
  696|  2.23k|inline constexpr auto store_any(Ts... ins) {
  697|  2.23k|   return store_any<endianness, OutR>(std::array{ins...});
  698|  2.23k|}
_ZN5Botan6detail9store_anyILNSt3__16endianE57005ENS0_10AutoDetectETkNS_6ranges14spanable_rangeENS2_5arrayImLm1EEEQoooosr3stdE7same_asIS4_T0_Eaasr6rangesE25statically_spanable_rangeIS8_Esr3stdE21default_initializableIS8_Esr8conceptsE21resizable_byte_bufferIS8_EEEDaOT1_:
  663|  2.23k|inline constexpr auto store_any(InR&& in_range) {
  664|  2.23k|   auto out = []([[maybe_unused]] const auto& in) {
  665|  2.23k|      if constexpr(std::same_as<AutoDetect, OutR>) {
  666|  2.23k|         if constexpr(ranges::statically_spanable_range<InR>) {
  667|  2.23k|            constexpr size_t bytes = decltype(std::span{in})::extent * sizeof(std::ranges::range_value_t<InR>);
  668|  2.23k|            return std::array<uint8_t, bytes>();
  669|  2.23k|         } else {
  670|  2.23k|            static_assert(
  671|  2.23k|               !std::same_as<AutoDetect, OutR>,
  672|  2.23k|               "cannot infer a suitable result container type from the given parameters at compile time, please specify it explicitly");
  673|  2.23k|         }
  674|  2.23k|      } else if constexpr(concepts::resizable_byte_buffer<OutR>) {
  675|  2.23k|         return OutR(std::span{in}.size_bytes());
  676|  2.23k|      } else {
  677|  2.23k|         return OutR{};
  678|  2.23k|      }
  679|  2.23k|   }(in_range);
  680|       |
  681|  2.23k|   store_any<endianness, std::ranges::range_value_t<InR>>(out, std::forward<InR>(in_range));
  682|  2.23k|   return out;
  683|  2.23k|}
_ZZN5Botan6detail9store_anyILNSt3__16endianE57005ENS0_10AutoDetectETkNS_6ranges14spanable_rangeENS2_5arrayImLm1EEEQoooosr3stdE7same_asIS4_T0_Eaasr6rangesE25statically_spanable_rangeIS8_Esr3stdE21default_initializableIS8_Esr8conceptsE21resizable_byte_bufferIS8_EEEDaOT1_ENKUlRKT_E_clIS7_EEDaSD_:
  664|  2.23k|   auto out = []([[maybe_unused]] const auto& in) {
  665|  2.23k|      if constexpr(std::same_as<AutoDetect, OutR>) {
  666|  2.23k|         if constexpr(ranges::statically_spanable_range<InR>) {
  667|  2.23k|            constexpr size_t bytes = decltype(std::span{in})::extent * sizeof(std::ranges::range_value_t<InR>);
  668|  2.23k|            return std::array<uint8_t, bytes>();
  669|       |         } else {
  670|       |            static_assert(
  671|       |               !std::same_as<AutoDetect, OutR>,
  672|       |               "cannot infer a suitable result container type from the given parameters at compile time, please specify it explicitly");
  673|       |         }
  674|       |      } else if constexpr(concepts::resizable_byte_buffer<OutR>) {
  675|       |         return OutR(std::span{in}.size_bytes());
  676|       |      } else {
  677|       |         return OutR{};
  678|       |      }
  679|  2.23k|   }(in_range);
_ZN5Botan6detail9store_anyILNSt3__16endianE57005EmTkNS_6ranges23contiguous_output_rangeIhEERNS2_5arrayIhLm8EEETkNS4_14spanable_rangeENS6_ImLm1EEEQoosr3stdE7same_asINS0_10AutoDetectET0_Esr3stdE7same_asISB_NS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT2_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISJ_EESK_E4type10value_typeEEEEvOT1_RKSG_:
  603|  2.23k|inline constexpr void store_any(OutR&& out /* NOLINT(*-std-forward) */, const InR& in) {
  604|  2.23k|   ranges::assert_equal_byte_lengths(out, in);
  605|  2.23k|   using element_type = std::ranges::range_value_t<InR>;
  606|       |
  607|  2.23k|   auto store_elementwise = [&] {
  608|  2.23k|      constexpr size_t bytes_per_element = sizeof(element_type);
  609|  2.23k|      std::span<uint8_t> out_s(out);
  610|  2.23k|      for(auto in_elem : in) {
  611|  2.23k|         store_any<endianness, element_type>(out_s.template first<bytes_per_element>(), in_elem);
  612|  2.23k|         out_s = out_s.subspan(bytes_per_element);
  613|  2.23k|      }
  614|  2.23k|   };
  615|       |
  616|       |   // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  617|       |   // internally to copy ranges on a byte-by-byte basis, which is not allowed
  618|       |   // in a `constexpr` context.
  619|  2.23k|   if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (619:7): [Folded, False: 2.23k]
  ------------------
  620|      0|      store_elementwise();
  621|  2.23k|   } else {
  622|  2.23k|      if constexpr(endianness == std::endian::native && !custom_storable<element_type>) {
  623|  2.23k|         typecast_copy(out, in);
  624|       |      } else {
  625|       |         store_elementwise();
  626|       |      }
  627|  2.23k|   }
  628|  2.23k|}
_ZN5Botan6detail9store_anyILNSt3__16endianE64206ENS0_10AutoDetectETkNS0_20unsigned_integralishEmQoosr3stdE7same_asIS4_T0_Esr3stdE7same_asIT1_S5_EEEvS6_Ph:
  711|  42.3k|inline constexpr void store_any(T in, uint8_t out[]) {
  712|       |   // asserts that *out points to enough bytes to write into
  713|  42.3k|   store_any<endianness, InT>(in, std::span<uint8_t, sizeof(T)>(out, sizeof(T)));
  714|  42.3k|}
_ZN5Botan6detail9store_anyILNSt3__16endianE64206ENS0_10AutoDetectETkNS0_20unsigned_integralishEmTkNS_6ranges23contiguous_output_rangeIhEENS2_4spanIhLm8EEEQsr3stdE7same_asIS4_T0_EEEvT1_OT2_:
  646|  42.3k|inline constexpr void store_any(T in, OutR&& out_range) {
  647|  42.3k|   store_any<endianness, T>(in, std::forward<OutR>(out_range));
  648|  42.3k|}
_ZN5Botan6detail9store_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges23contiguous_output_rangeIhEENS2_4spanIhLm8EEEQnt15custom_storableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEEvS9_OT1_:
  525|  42.3k|inline constexpr void store_any(WrappedInT wrapped_in, OutR&& out_range) {
  526|  42.3k|   const auto in = detail::unwrap_strong_type_or_enum(wrapped_in);
  527|  42.3k|   using InT = decltype(in);
  528|  42.3k|   ranges::assert_exact_byte_length<sizeof(in)>(out_range);
  529|  42.3k|   const std::span out{out_range};
  530|       |
  531|       |   // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  532|       |   // internally to copy ranges on a byte-by-byte basis, which is not allowed
  533|       |   // in a `constexpr` context.
  534|  42.3k|   if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (534:7): [Folded, False: 42.3k]
  ------------------
  535|      0|      return fallback_store_any<endianness, InT>(in, std::forward<OutR>(out_range));
  536|  42.3k|   } else {
  537|       |      if constexpr(sizeof(InT) == 1) {
  538|       |         out[0] = static_cast<uint8_t>(in);
  539|       |      } else if constexpr(endianness == std::endian::native) {
  540|       |         typecast_copy(out, in);
  541|  42.3k|      } else {
  542|  42.3k|         static_assert(opposite(endianness) == std::endian::native);
  543|  42.3k|         typecast_copy(out, reverse_bytes(in));
  544|  42.3k|      }
  545|  42.3k|   }
  546|  42.3k|}
_ZN5Botan8store_beINS_6detail10AutoDetectEJRKmPhEEEDaDpOT0_:
  745|  42.3k|inline constexpr auto store_be(ParamTs&&... params) {
  746|  42.3k|   return detail::store_any<std::endian::big, ModifierT>(std::forward<ParamTs>(params)...);
  747|  42.3k|}
_ZN5Botan11copy_out_beITkNS_6ranges14spanable_rangeENSt3__16vectorIjNS_16secure_allocatorIjEEEEEEvNS2_4spanIhLm18446744073709551615EEERKT_:
  773|  42.1k|inline void copy_out_be(std::span<uint8_t> out, const InR& in) {
  774|  42.1k|   using T = std::ranges::range_value_t<InR>;
  775|  42.1k|   std::span<const T> in_s{in};
  776|  42.1k|   const auto remaining_bytes = detail::copy_out_any_word_aligned_portion<std::endian::big>(out, in_s);
  777|       |
  778|       |   // copy remaining bytes as a partial word
  779|  42.1k|   for(size_t i = 0; i < remaining_bytes; ++i) {
  ------------------
  |  Branch (779:22): [True: 0, False: 42.1k]
  ------------------
  780|      0|      out[i] = get_byte_var(i, in_s.front());
  781|      0|   }
  782|  42.1k|}
_ZN5Botan6detail33copy_out_any_word_aligned_portionILNSt3__16endianE64206ETkNS0_20unsigned_integralishEjEEmRNS2_4spanIhLm18446744073709551615EEERNS4_IKT0_Lm18446744073709551615EEE:
  752|  42.1k|inline size_t copy_out_any_word_aligned_portion(std::span<uint8_t>& out, std::span<const T>& in) {
  753|  42.1k|   const size_t full_words = out.size() / sizeof(T);
  754|  42.1k|   const size_t full_word_bytes = full_words * sizeof(T);
  755|  42.1k|   const size_t remaining_bytes = out.size() - full_word_bytes;
  756|  42.1k|   BOTAN_ASSERT_NOMSG(in.size_bytes() >= full_word_bytes + remaining_bytes);
  ------------------
  |  |   84|  42.1k|   do {                                                                     \
  |  |   85|  42.1k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  42.1k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 42.1k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  42.1k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 42.1k]
  |  |  ------------------
  ------------------
  757|       |
  758|       |   // copy full words
  759|  42.1k|   store_any<endianness, T>(out.first(full_word_bytes), in.first(full_words));
  760|  42.1k|   out = out.subspan(full_word_bytes);
  761|  42.1k|   in = in.subspan(full_words);
  762|       |
  763|  42.1k|   return remaining_bytes;
  764|  42.1k|}
_ZN5Botan6detail9store_anyILNSt3__16endianE64206EjTkNS_6ranges23contiguous_output_rangeIhEENS2_4spanIhLm18446744073709551615EEETkNS4_14spanable_rangeENS6_IKjLm18446744073709551615EEEQoosr3stdE7same_asINS0_10AutoDetectET0_Esr3stdE7same_asISB_NS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT2_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISJ_EESK_E4type10value_typeEEEEvOT1_RKSG_:
  603|  42.1k|inline constexpr void store_any(OutR&& out /* NOLINT(*-std-forward) */, const InR& in) {
  604|  42.1k|   ranges::assert_equal_byte_lengths(out, in);
  605|  42.1k|   using element_type = std::ranges::range_value_t<InR>;
  606|       |
  607|  42.1k|   auto store_elementwise = [&] {
  608|  42.1k|      constexpr size_t bytes_per_element = sizeof(element_type);
  609|  42.1k|      std::span<uint8_t> out_s(out);
  610|  42.1k|      for(auto in_elem : in) {
  611|  42.1k|         store_any<endianness, element_type>(out_s.template first<bytes_per_element>(), in_elem);
  612|  42.1k|         out_s = out_s.subspan(bytes_per_element);
  613|  42.1k|      }
  614|  42.1k|   };
  615|       |
  616|       |   // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  617|       |   // internally to copy ranges on a byte-by-byte basis, which is not allowed
  618|       |   // in a `constexpr` context.
  619|  42.1k|   if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (619:7): [Folded, False: 42.1k]
  ------------------
  620|      0|      store_elementwise();
  621|  42.1k|   } else {
  622|       |      if constexpr(endianness == std::endian::native && !custom_storable<element_type>) {
  623|       |         typecast_copy(out, in);
  624|  42.1k|      } else {
  625|  42.1k|         store_elementwise();
  626|  42.1k|      }
  627|  42.1k|   }
  628|  42.1k|}
_ZZN5Botan6detail9store_anyILNSt3__16endianE64206EjTkNS_6ranges23contiguous_output_rangeIhEENS2_4spanIhLm18446744073709551615EEETkNS4_14spanable_rangeENS6_IKjLm18446744073709551615EEEQoosr3stdE7same_asINS0_10AutoDetectET0_Esr3stdE7same_asISB_NS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT2_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISJ_EESK_E4type10value_typeEEEEvOT1_RKSG_ENKUlvE_clEv:
  607|  42.1k|   auto store_elementwise = [&] {
  608|  42.1k|      constexpr size_t bytes_per_element = sizeof(element_type);
  609|  42.1k|      std::span<uint8_t> out_s(out);
  610|   321k|      for(auto in_elem : in) {
  ------------------
  |  Branch (610:24): [True: 321k, False: 42.1k]
  ------------------
  611|   321k|         store_any<endianness, element_type>(out_s.template first<bytes_per_element>(), in_elem);
  612|   321k|         out_s = out_s.subspan(bytes_per_element);
  613|   321k|      }
  614|  42.1k|   };
_ZN5Botan7load_beImJNSt3__14spanIKhLm8EEEEEEDaDpOT0_:
  504|    252|inline constexpr auto load_be(ParamTs&&... params) {
  505|    252|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|    252|}
_ZN5Botan7load_beImJRNSt3__15arrayIhLm8EEEEEEDaDpOT0_:
  504|  3.08k|inline constexpr auto load_be(ParamTs&&... params) {
  505|  3.08k|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|  3.08k|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEERNS2_5arrayIhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|  3.08k|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|  3.08k|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|  3.08k|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|  3.08k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  3.08k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|  3.08k|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  3.08k|      } else {
  289|  3.08k|         const std::span in{in_range};
  290|  3.08k|         if constexpr(sizeof(OutT) == 1) {
  291|  3.08k|            return static_cast<OutT>(in[0]);
  292|  3.08k|         } else if constexpr(endianness == std::endian::native) {
  293|  3.08k|            return typecast_copy<OutT>(in);
  294|  3.08k|         } else {
  295|  3.08k|            static_assert(opposite(endianness) == std::endian::native);
  296|  3.08k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  3.08k|         }
  298|  3.08k|      }
  299|  3.08k|   }());
  300|  3.08k|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEERNS2_5arrayIhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|  3.08k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  3.08k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 3.08k]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  3.08k|      } else {
  289|  3.08k|         const std::span in{in_range};
  290|       |         if constexpr(sizeof(OutT) == 1) {
  291|       |            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|  3.08k|         } else {
  295|  3.08k|            static_assert(opposite(endianness) == std::endian::native);
  296|  3.08k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  3.08k|         }
  298|  3.08k|      }
  299|  3.08k|   }());
_ZN5Botan7load_beIjJPKhRmEEEDaDpOT0_:
  504|    182|inline constexpr auto load_be(ParamTs&&... params) {
  505|    182|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|    182|}

_ZN5Botan18MerkleDamgard_HashINS_5SHA_1EEC2Ev:
   42|  1.32k|      MerkleDamgard_Hash() { clear(); }
_ZN5Botan18MerkleDamgard_HashINS_5SHA_1EE5clearEv:
   70|  6.60k|      void clear() {
   71|  6.60k|         MD::init(m_digest);
   72|  6.60k|         m_buffer.clear();
   73|  6.60k|         m_count = 0;
   74|  6.60k|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EEC2Ev:
   42|  10.4k|      MerkleDamgard_Hash() { clear(); }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE5clearEv:
   70|  47.2k|      void clear() {
   71|  47.2k|         MD::init(m_digest);
   72|  47.2k|         m_buffer.clear();
   73|  47.2k|         m_count = 0;
   74|  47.2k|      }
_ZN5Botan18MerkleDamgard_HashINS_5SHA_1EE6updateENSt3__14spanIKhLm18446744073709551615EEE:
   44|  5.28k|      void update(std::span<const uint8_t> input) {
   45|  5.28k|         BufferSlicer in(input);
   46|       |
   47|  11.8k|         while(!in.empty()) {
  ------------------
  |  Branch (47:16): [True: 6.60k, False: 5.28k]
  ------------------
   48|  6.60k|            if(const auto one_block = m_buffer.handle_unaligned_data(in)) {
  ------------------
  |  Branch (48:27): [True: 0, False: 6.60k]
  ------------------
   49|      0|               MD::compress_n(m_digest, one_block.value(), 1);
   50|      0|            }
   51|       |
   52|  6.60k|            if(m_buffer.in_alignment()) {
  ------------------
  |  Branch (52:16): [True: 1.32k, False: 5.28k]
  ------------------
   53|  1.32k|               const auto [aligned_data, full_blocks] = m_buffer.aligned_data_to_process(in);
   54|  1.32k|               if(full_blocks > 0) {
  ------------------
  |  Branch (54:19): [True: 1.32k, False: 0]
  ------------------
   55|  1.32k|                  MD::compress_n(m_digest, aligned_data, full_blocks);
   56|  1.32k|               }
   57|  1.32k|            }
   58|  6.60k|         }
   59|       |
   60|  5.28k|         m_count += input.size();
   61|  5.28k|      }
_ZN5Botan18MerkleDamgard_HashINS_5SHA_1EE5finalENSt3__14spanIhLm18446744073709551615EEE:
   63|  5.28k|      void final(std::span<uint8_t> output) {
   64|  5.28k|         append_padding_bit();
   65|  5.28k|         append_counter_and_finalize();
   66|  5.28k|         copy_output(output);
   67|  5.28k|         clear();
   68|  5.28k|      }
_ZN5Botan18MerkleDamgard_HashINS_5SHA_1EE18append_padding_bitEv:
   77|  5.28k|      void append_padding_bit() {
   78|  5.28k|         BOTAN_ASSERT_NOMSG(!m_buffer.ready_to_consume());
  ------------------
  |  |   84|  5.28k|   do {                                                                     \
  |  |   85|  5.28k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  5.28k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 5.28k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  5.28k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 5.28k]
  |  |  ------------------
  ------------------
   79|  5.28k|         if constexpr(MD::bit_endianness == MD_Endian::Big) {
   80|  5.28k|            const uint8_t final_byte = 0x80;
   81|  5.28k|            m_buffer.append({&final_byte, 1});
   82|       |         } else {
   83|       |            const uint8_t final_byte = 0x01;
   84|       |            m_buffer.append({&final_byte, 1});
   85|       |         }
   86|  5.28k|      }
_ZN5Botan18MerkleDamgard_HashINS_5SHA_1EE27append_counter_and_finalizeEv:
   88|  5.28k|      void append_counter_and_finalize() {
   89|       |         // Compress the remaining data if the final data block does not provide
   90|       |         // enough space for the counter bytes.
   91|  5.28k|         if(m_buffer.elements_until_alignment() < MD::ctr_bytes) {
  ------------------
  |  Branch (91:13): [True: 0, False: 5.28k]
  ------------------
   92|      0|            m_buffer.fill_up_with_zeros();
   93|      0|            MD::compress_n(m_digest, m_buffer.consume(), 1);
   94|      0|         }
   95|       |
   96|       |         // Make sure that any remaining bytes in the very last block are zero.
   97|  5.28k|         BOTAN_ASSERT_NOMSG(m_buffer.elements_until_alignment() >= MD::ctr_bytes);
  ------------------
  |  |   84|  5.28k|   do {                                                                     \
  |  |   85|  5.28k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  5.28k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 5.28k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  5.28k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 5.28k]
  |  |  ------------------
  ------------------
   98|  5.28k|         m_buffer.fill_up_with_zeros();
   99|       |
  100|       |         // Replace a bunch of the right-most zero-padding with the counter bytes.
  101|  5.28k|         const uint64_t bit_count = m_count * 8;
  102|  5.28k|         auto last_bytes = m_buffer.directly_modify_last(sizeof(bit_count));
  103|  5.28k|         if constexpr(MD::byte_endianness == MD_Endian::Big) {
  104|  5.28k|            store_be(bit_count, last_bytes.data());
  105|       |         } else {
  106|       |            store_le(bit_count, last_bytes.data());
  107|       |         }
  108|       |
  109|       |         // Compress the very last block.
  110|  5.28k|         MD::compress_n(m_digest, m_buffer.consume(), 1);
  111|  5.28k|      }
_ZN5Botan18MerkleDamgard_HashINS_5SHA_1EE11copy_outputENSt3__14spanIhLm18446744073709551615EEE:
  113|  5.28k|      void copy_output(std::span<uint8_t> output) {
  114|  5.28k|         BOTAN_ASSERT_NOMSG(output.size() >= MD::output_bytes);
  ------------------
  |  |   84|  5.28k|   do {                                                                     \
  |  |   85|  5.28k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  5.28k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 5.28k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  5.28k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 5.28k]
  |  |  ------------------
  ------------------
  115|       |
  116|  5.28k|         if constexpr(MD::byte_endianness == MD_Endian::Big) {
  117|  5.28k|            copy_out_be(output.first(MD::output_bytes), m_digest);
  118|       |         } else {
  119|       |            copy_out_le(output.first(MD::output_bytes), m_digest);
  120|       |         }
  121|  5.28k|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE6updateENSt3__14spanIKhLm18446744073709551615EEE:
   44|  39.5k|      void update(std::span<const uint8_t> input) {
   45|  39.5k|         BufferSlicer in(input);
   46|       |
   47|  90.2k|         while(!in.empty()) {
  ------------------
  |  Branch (47:16): [True: 50.7k, False: 39.5k]
  ------------------
   48|  50.7k|            if(const auto one_block = m_buffer.handle_unaligned_data(in)) {
  ------------------
  |  Branch (48:27): [True: 10.6k, False: 40.1k]
  ------------------
   49|  10.6k|               MD::compress_n(m_digest, one_block.value(), 1);
   50|  10.6k|            }
   51|       |
   52|  50.7k|            if(m_buffer.in_alignment()) {
  ------------------
  |  Branch (52:16): [True: 12.5k, False: 38.1k]
  ------------------
   53|  12.5k|               const auto [aligned_data, full_blocks] = m_buffer.aligned_data_to_process(in);
   54|  12.5k|               if(full_blocks > 0) {
  ------------------
  |  Branch (54:19): [True: 3.00k, False: 9.56k]
  ------------------
   55|  3.00k|                  MD::compress_n(m_digest, aligned_data, full_blocks);
   56|  3.00k|               }
   57|  12.5k|            }
   58|  50.7k|         }
   59|       |
   60|  39.5k|         m_count += input.size();
   61|  39.5k|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE5finalENSt3__14spanIhLm18446744073709551615EEE:
   63|  36.8k|      void final(std::span<uint8_t> output) {
   64|  36.8k|         append_padding_bit();
   65|  36.8k|         append_counter_and_finalize();
   66|  36.8k|         copy_output(output);
   67|  36.8k|         clear();
   68|  36.8k|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE18append_padding_bitEv:
   77|  36.8k|      void append_padding_bit() {
   78|  36.8k|         BOTAN_ASSERT_NOMSG(!m_buffer.ready_to_consume());
  ------------------
  |  |   84|  36.8k|   do {                                                                     \
  |  |   85|  36.8k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  36.8k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 36.8k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  36.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 36.8k]
  |  |  ------------------
  ------------------
   79|  36.8k|         if constexpr(MD::bit_endianness == MD_Endian::Big) {
   80|  36.8k|            const uint8_t final_byte = 0x80;
   81|  36.8k|            m_buffer.append({&final_byte, 1});
   82|       |         } else {
   83|       |            const uint8_t final_byte = 0x01;
   84|       |            m_buffer.append({&final_byte, 1});
   85|       |         }
   86|  36.8k|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE27append_counter_and_finalizeEv:
   88|  36.8k|      void append_counter_and_finalize() {
   89|       |         // Compress the remaining data if the final data block does not provide
   90|       |         // enough space for the counter bytes.
   91|  36.8k|         if(m_buffer.elements_until_alignment() < MD::ctr_bytes) {
  ------------------
  |  Branch (91:13): [True: 3.56k, False: 33.2k]
  ------------------
   92|  3.56k|            m_buffer.fill_up_with_zeros();
   93|  3.56k|            MD::compress_n(m_digest, m_buffer.consume(), 1);
   94|  3.56k|         }
   95|       |
   96|       |         // Make sure that any remaining bytes in the very last block are zero.
   97|  36.8k|         BOTAN_ASSERT_NOMSG(m_buffer.elements_until_alignment() >= MD::ctr_bytes);
  ------------------
  |  |   84|  36.8k|   do {                                                                     \
  |  |   85|  36.8k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  36.8k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 36.8k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  36.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 36.8k]
  |  |  ------------------
  ------------------
   98|  36.8k|         m_buffer.fill_up_with_zeros();
   99|       |
  100|       |         // Replace a bunch of the right-most zero-padding with the counter bytes.
  101|  36.8k|         const uint64_t bit_count = m_count * 8;
  102|  36.8k|         auto last_bytes = m_buffer.directly_modify_last(sizeof(bit_count));
  103|  36.8k|         if constexpr(MD::byte_endianness == MD_Endian::Big) {
  104|  36.8k|            store_be(bit_count, last_bytes.data());
  105|       |         } else {
  106|       |            store_le(bit_count, last_bytes.data());
  107|       |         }
  108|       |
  109|       |         // Compress the very last block.
  110|  36.8k|         MD::compress_n(m_digest, m_buffer.consume(), 1);
  111|  36.8k|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE11copy_outputENSt3__14spanIhLm18446744073709551615EEE:
  113|  36.8k|      void copy_output(std::span<uint8_t> output) {
  114|  36.8k|         BOTAN_ASSERT_NOMSG(output.size() >= MD::output_bytes);
  ------------------
  |  |   84|  36.8k|   do {                                                                     \
  |  |   85|  36.8k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  36.8k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 36.8k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  36.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 36.8k]
  |  |  ------------------
  ------------------
  115|       |
  116|  36.8k|         if constexpr(MD::byte_endianness == MD_Endian::Big) {
  117|  36.8k|            copy_out_be(output.first(MD::output_bytes), m_digest);
  118|       |         } else {
  119|       |            copy_out_le(output.first(MD::output_bytes), m_digest);
  120|       |         }
  121|  36.8k|      }

_ZN5Botan15bytes_to_stringENSt3__14spanIKhLm18446744073709551615EEE:
   76|  6.05k|inline std::string bytes_to_string(std::span<const uint8_t> bytes) {
   77|  6.05k|   return std::string(reinterpret_cast<const char*>(bytes.data()), bytes.size());
   78|  6.05k|}
_ZN5Botan14zeroize_bufferITkNSt3__117unsigned_integralEhEEvPT_m:
   37|  99.1k|inline void zeroize_buffer(T buf[], size_t n) {
   38|  99.1k|   if(n > 0) {
  ------------------
  |  Branch (38:7): [True: 99.1k, False: 0]
  ------------------
   39|  99.1k|      std::memset(buf, 0, sizeof(T) * n);
   40|  99.1k|   }
   41|  99.1k|}

_ZN5Botan10bigint_cmpITkNS_8WordTypeEmEEiPKT_mS3_m:
  460|    649|inline constexpr int32_t bigint_cmp(const W x[], size_t x_size, const W y[], size_t y_size) {
  461|    649|   static_assert(sizeof(W) >= sizeof(uint32_t), "Size assumption");
  462|       |
  463|    649|   const W LT = static_cast<W>(-1);
  464|    649|   const W EQ = 0;
  465|    649|   const W GT = 1;
  466|       |
  467|    649|   const size_t common_elems = std::min(x_size, y_size);
  468|       |
  469|    649|   W result = EQ;  // until found otherwise
  470|       |
  471|  1.15k|   for(size_t i = 0; i != common_elems; i++) {
  ------------------
  |  Branch (471:22): [True: 510, False: 649]
  ------------------
  472|    510|      const auto is_eq = CT::Mask<W>::is_equal(x[i], y[i]);
  473|    510|      const auto is_lt = CT::Mask<W>::is_lt(x[i], y[i]);
  474|       |
  475|    510|      result = is_eq.select(result, is_lt.select(LT, GT));
  476|    510|   }
  477|       |
  478|    649|   if(x_size < y_size) {
  ------------------
  |  Branch (478:7): [True: 139, False: 510]
  ------------------
  479|    139|      W mask = 0;
  480|    278|      for(size_t i = x_size; i != y_size; i++) {
  ------------------
  |  Branch (480:30): [True: 139, False: 139]
  ------------------
  481|    139|         mask |= y[i];
  482|    139|      }
  483|       |
  484|       |      // If any bits were set in high part of y, then x < y
  485|    139|      result = CT::Mask<W>::is_zero(mask).select(result, LT);
  486|    510|   } else if(y_size < x_size) {
  ------------------
  |  Branch (486:14): [True: 0, False: 510]
  ------------------
  487|      0|      W mask = 0;
  488|      0|      for(size_t i = y_size; i != x_size; i++) {
  ------------------
  |  Branch (488:30): [True: 0, False: 0]
  ------------------
  489|      0|         mask |= x[i];
  490|      0|      }
  491|       |
  492|       |      // If any bits were set in high part of x, then x > y
  493|      0|      result = CT::Mask<W>::is_zero(mask).select(result, GT);
  494|      0|   }
  495|       |
  496|    649|   CT::unpoison(result);
  497|    649|   BOTAN_DEBUG_ASSERT(result == LT || result == GT || result == EQ);
  ------------------
  |  |  137|    649|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|    649|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 649]
  |  |  ------------------
  ------------------
  498|    649|   return static_cast<int32_t>(result);
  499|    649|}

_ZN5Botan4rotlILm5ETkNSt3__117unsigned_integralEjEET0_S2_QaagtT_Li0EltT_mlLi8EstS2_:
   25|   528k|{
   26|   528k|   return static_cast<T>((input << ROT) | (input >> (8 * sizeof(T) - ROT)));
   27|   528k|}
_ZN5Botan4rotlILm30ETkNSt3__117unsigned_integralEjEET0_S2_QaagtT_Li0EltT_mlLi8EstS2_:
   25|   528k|{
   26|   528k|   return static_cast<T>((input << ROT) | (input >> (8 * sizeof(T) - ROT)));
   27|   528k|}
_ZN5Botan3rhoILm6ELm11ELm25ETkNSt3__117unsigned_integralEjEET2_S2_:
   53|  3.58M|BOTAN_FORCE_INLINE constexpr T rho(T x) {
   54|  3.58M|   return rotr<R1>(x) ^ rotr<R2>(x) ^ rotr<R3>(x);
   55|  3.58M|}
_ZN5Botan4rotrILm6ETkNSt3__117unsigned_integralEjEET0_S2_QaagtT_Li0EltT_mlLi8EstS2_:
   37|  3.58M|{
   38|  3.58M|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   39|  3.58M|}
_ZN5Botan4rotrILm11ETkNSt3__117unsigned_integralEjEET0_S2_QaagtT_Li0EltT_mlLi8EstS2_:
   37|  3.58M|{
   38|  3.58M|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   39|  3.58M|}
_ZN5Botan4rotrILm25ETkNSt3__117unsigned_integralEjEET0_S2_QaagtT_Li0EltT_mlLi8EstS2_:
   37|  3.58M|{
   38|  3.58M|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   39|  3.58M|}
_ZN5Botan3rhoILm2ELm13ELm22ETkNSt3__117unsigned_integralEjEET2_S2_:
   53|  3.58M|BOTAN_FORCE_INLINE constexpr T rho(T x) {
   54|  3.58M|   return rotr<R1>(x) ^ rotr<R2>(x) ^ rotr<R3>(x);
   55|  3.58M|}
_ZN5Botan4rotrILm2ETkNSt3__117unsigned_integralEjEET0_S2_QaagtT_Li0EltT_mlLi8EstS2_:
   37|  3.58M|{
   38|  3.58M|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   39|  3.58M|}
_ZN5Botan4rotrILm13ETkNSt3__117unsigned_integralEjEET0_S2_QaagtT_Li0EltT_mlLi8EstS2_:
   37|  3.58M|{
   38|  3.58M|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   39|  3.58M|}
_ZN5Botan4rotrILm22ETkNSt3__117unsigned_integralEjEET0_S2_QaagtT_Li0EltT_mlLi8EstS2_:
   37|  3.58M|{
   38|  3.58M|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   39|  3.58M|}

_ZN5Botan8round_upEmm:
   26|  9.18k|constexpr inline size_t round_up(size_t n, size_t align_to) {
   27|       |   // Arguably returning n in this case would also be sensible
   28|  9.18k|   BOTAN_ARG_CHECK(align_to != 0, "align_to must not be 0");
  ------------------
  |  |   35|  9.18k|   do {                                                          \
  |  |   36|  9.18k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  9.18k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 9.18k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  9.18k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 9.18k]
  |  |  ------------------
  ------------------
   29|       |
   30|  9.18k|   if(n % align_to > 0) {
  ------------------
  |  Branch (30:7): [True: 8.82k, False: 358]
  ------------------
   31|  8.82k|      const size_t adj = align_to - (n % align_to);
   32|  8.82k|      BOTAN_ARG_CHECK(n + adj >= n, "Integer overflow during rounding");
  ------------------
  |  |   35|  8.82k|   do {                                                          \
  |  |   36|  8.82k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  8.82k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 8.82k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  8.82k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 8.82k]
  |  |  ------------------
  ------------------
   33|  8.82k|      n += adj;
   34|  8.82k|   }
   35|  9.18k|   return n;
   36|  9.18k|}

_ZNK5Botan5SHA_113output_lengthEv:
   34|  9.24k|      size_t output_length() const override { return 20; }

_ZN5Botan6SHA1_F2F1EjRjjjS1_j:
   21|   132k|inline void F1(uint32_t A, uint32_t& B, uint32_t C, uint32_t D, uint32_t& E, uint32_t M) {
   22|   132k|   E += choose(B, C, D) + M + rotl<5>(A);
   23|   132k|   B = rotl<30>(B);
   24|   132k|}
_ZN5Botan6SHA1_F2F2EjRjjjS1_j:
   26|   132k|inline void F2(uint32_t A, uint32_t& B, uint32_t C, uint32_t D, uint32_t& E, uint32_t M) {
   27|   132k|   E += (B ^ C ^ D) + M + rotl<5>(A);
   28|   132k|   B = rotl<30>(B);
   29|   132k|}
_ZN5Botan6SHA1_F2F3EjRjjjS1_j:
   31|   132k|inline void F3(uint32_t A, uint32_t& B, uint32_t C, uint32_t D, uint32_t& E, uint32_t M) {
   32|   132k|   E += majority(B, C, D) + M + rotl<5>(A);
   33|   132k|   B = rotl<30>(B);
   34|   132k|}
_ZN5Botan6SHA1_F2F4EjRjjjS1_j:
   37|   132k|inline void F4(uint32_t A, uint32_t& B, uint32_t C, uint32_t D, uint32_t& E, uint32_t M) {
   38|   132k|   E += (B ^ C ^ D) + M + rotl<5>(A);
   39|   132k|   B = rotl<30>(B);
   40|   132k|}

_ZNK5Botan7SHA_25613output_lengthEv:
   75|  39.5k|      size_t output_length() const override { return output_bytes; }

_ZN5Botan9SHA2_32_FEjjjRjjjjS0_j:
   56|  3.58M|   uint32_t A, uint32_t B, uint32_t C, uint32_t& D, uint32_t E, uint32_t F, uint32_t G, uint32_t& H, uint32_t M) {
   57|  3.58M|   H += rho<6, 11, 25>(E) + choose(E, F, G) + M;
   58|  3.58M|   D += H;
   59|  3.58M|   H += rho<2, 13, 22>(A) + majority(A, B, C);
   60|  3.58M|}

_ZN5Botan9SIMD_4x32C2EDv2_x:
 1008|  12.2M|      explicit BOTAN_FN_ISA_SIMD_4X32 SIMD_4x32(native_simd_type x) noexcept : m_simd(x) {}
_ZN5Botan9SIMD_4x327load_beEPKv:
  198|   215k|      static SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 load_be(const void* in) noexcept {
  199|   215k|#if defined(BOTAN_SIMD_USE_SSSE3) || defined(BOTAN_SIMD_USE_LSX) || defined(BOTAN_SIMD_USE_SIMD128)
  200|   215k|         return load_le(in).bswap();
  201|       |
  202|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  203|       |         uint32_t R0 = Botan::load_be<uint32_t>(reinterpret_cast<const uint8_t*>(in), 0);
  204|       |         uint32_t R1 = Botan::load_be<uint32_t>(reinterpret_cast<const uint8_t*>(in), 1);
  205|       |         uint32_t R2 = Botan::load_be<uint32_t>(reinterpret_cast<const uint8_t*>(in), 2);
  206|       |         uint32_t R3 = Botan::load_be<uint32_t>(reinterpret_cast<const uint8_t*>(in), 3);
  207|       |         __vector unsigned int val = {R0, R1, R2, R3};
  208|       |         return SIMD_4x32(val);
  209|       |
  210|       |#elif defined(BOTAN_SIMD_USE_NEON)
  211|       |         SIMD_4x32 l(vld1q_u32(static_cast<const uint32_t*>(in)));
  212|       |         if constexpr(std::endian::native == std::endian::little) {
  213|       |            return l.bswap();
  214|       |         } else {
  215|       |            return l;
  216|       |         }
  217|       |#endif
  218|   215k|      }
_ZN5Botan9SIMD_4x327load_leEPKv:
  171|  1.07M|      static SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 load_le(const void* in) noexcept {
  172|  1.07M|#if defined(BOTAN_SIMD_USE_SSSE3)
  173|  1.07M|         return SIMD_4x32(_mm_loadu_si128(reinterpret_cast<const __m128i*>(in)));
  174|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  175|       |         uint32_t R0 = Botan::load_le<uint32_t>(reinterpret_cast<const uint8_t*>(in), 0);
  176|       |         uint32_t R1 = Botan::load_le<uint32_t>(reinterpret_cast<const uint8_t*>(in), 1);
  177|       |         uint32_t R2 = Botan::load_le<uint32_t>(reinterpret_cast<const uint8_t*>(in), 2);
  178|       |         uint32_t R3 = Botan::load_le<uint32_t>(reinterpret_cast<const uint8_t*>(in), 3);
  179|       |         __vector unsigned int val = {R0, R1, R2, R3};
  180|       |         return SIMD_4x32(val);
  181|       |#elif defined(BOTAN_SIMD_USE_NEON)
  182|       |         SIMD_4x32 l(vld1q_u32(static_cast<const uint32_t*>(in)));
  183|       |         if constexpr(std::endian::native == std::endian::big) {
  184|       |            return l.bswap();
  185|       |         } else {
  186|       |            return l;
  187|       |         }
  188|       |#elif defined(BOTAN_SIMD_USE_LSX)
  189|       |         return SIMD_4x32(__lsx_vld(in, 0));
  190|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  191|       |         return SIMD_4x32(wasm_v128_load(in));
  192|       |#endif
  193|  1.07M|      }
_ZNK5Botan9SIMD_4x325bswapEv:
  586|   215k|      BOTAN_FN_ISA_SIMD_4X32 SIMD_4x32 bswap() const noexcept {
  587|   215k|#if defined(BOTAN_SIMD_USE_SSSE3)
  588|   215k|         const auto idx = _mm_set_epi8(12, 13, 14, 15, 8, 9, 10, 11, 4, 5, 6, 7, 0, 1, 2, 3);
  589|       |
  590|   215k|         return SIMD_4x32(_mm_shuffle_epi8(raw(), idx));
  591|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  592|       |   #ifdef BOTAN_SIMD_USE_VSX
  593|       |         return SIMD_4x32(vec_revb(m_simd));
  594|       |   #else
  595|       |         const __vector unsigned char rev[1] = {
  596|       |            {3, 2, 1, 0, 7, 6, 5, 4, 11, 10, 9, 8, 15, 14, 13, 12},
  597|       |         };
  598|       |
  599|       |         return SIMD_4x32(vec_perm(m_simd, m_simd, rev[0]));
  600|       |   #endif
  601|       |
  602|       |#elif defined(BOTAN_SIMD_USE_NEON)
  603|       |         return SIMD_4x32(vreinterpretq_u32_u8(vrev32q_u8(vreinterpretq_u8_u32(m_simd))));
  604|       |#elif defined(BOTAN_SIMD_USE_LSX)
  605|       |         return SIMD_4x32(__lsx_vshuf4i_b(m_simd, 0b00011011));
  606|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  607|       |         return SIMD_4x32(wasm_i8x16_shuffle(m_simd, m_simd, 3, 2, 1, 0, 7, 6, 5, 4, 11, 10, 9, 8, 15, 14, 13, 12));
  608|       |#endif
  609|   215k|      }
_ZNK5Botan9SIMD_4x323rawEv:
 1006|  10.1M|      native_simd_type BOTAN_FN_ISA_SIMD_4X32 raw() const noexcept { return m_simd; }
_ZNK5Botan9SIMD_4x32plERKS0_:
  395|   860k|      SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 operator+(const SIMD_4x32& other) const noexcept {
  396|   860k|         SIMD_4x32 retval(*this);
  397|   860k|         retval += other;
  398|   860k|         return retval;
  399|   860k|      }
_ZN5Botan9SIMD_4x32pLERKS0_:
  437|  3.44M|      void BOTAN_FN_ISA_SIMD_4X32 operator+=(const SIMD_4x32& other) noexcept {
  438|  3.44M|#if defined(BOTAN_SIMD_USE_SSSE3)
  439|  3.44M|         m_simd = _mm_add_epi32(m_simd, other.m_simd);
  440|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  441|       |         m_simd = vec_add(m_simd, other.m_simd);
  442|       |#elif defined(BOTAN_SIMD_USE_NEON)
  443|       |         m_simd = vaddq_u32(m_simd, other.m_simd);
  444|       |#elif defined(BOTAN_SIMD_USE_LSX)
  445|       |         m_simd = __lsx_vadd_w(m_simd, other.m_simd);
  446|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  447|       |         m_simd = wasm_i32x4_add(m_simd, other.m_simd);
  448|       |#endif
  449|  3.44M|      }
_ZNK5Botan9SIMD_4x328store_leEPj:
  228|   860k|      void BOTAN_FN_ISA_SIMD_4X32 store_le(uint32_t out[4]) const noexcept {
  229|   860k|         this->store_le(reinterpret_cast<uint8_t*>(out));
  230|   860k|      }
_ZNK5Botan9SIMD_4x328store_leEPh:
  243|   860k|      void BOTAN_FN_ISA_SIMD_4X32 store_le(uint8_t out[]) const noexcept {
  244|   860k|#if defined(BOTAN_SIMD_USE_SSSE3)
  245|       |
  246|   860k|         _mm_storeu_si128(reinterpret_cast<__m128i*>(out), raw());
  247|       |
  248|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  249|       |
  250|       |         union {
  251|       |               __vector unsigned int V;
  252|       |               uint32_t R[4];
  253|       |         } vec{};
  254|       |
  255|       |         // NOLINTNEXTLINE(*-union-access)
  256|       |         vec.V = raw();
  257|       |         // NOLINTNEXTLINE(*-union-access)
  258|       |         Botan::store_le(out, vec.R[0], vec.R[1], vec.R[2], vec.R[3]);
  259|       |
  260|       |#elif defined(BOTAN_SIMD_USE_NEON)
  261|       |         if constexpr(std::endian::native == std::endian::little) {
  262|       |            vst1q_u8(out, vreinterpretq_u8_u32(m_simd));
  263|       |         } else {
  264|       |            vst1q_u8(out, vreinterpretq_u8_u32(bswap().m_simd));
  265|       |         }
  266|       |#elif defined(BOTAN_SIMD_USE_LSX)
  267|       |         __lsx_vst(raw(), out, 0);
  268|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  269|       |         wasm_v128_store(out, m_simd);
  270|       |#endif
  271|   860k|      }
_ZN5Botan9SIMD_4x32eOERKS0_:
  465|  5.16M|      void BOTAN_FN_ISA_SIMD_4X32 operator^=(const SIMD_4x32& other) noexcept {
  466|  5.16M|#if defined(BOTAN_SIMD_USE_SSSE3)
  467|  5.16M|         m_simd = _mm_xor_si128(m_simd, other.m_simd);
  468|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  469|       |         m_simd = vec_xor(m_simd, other.m_simd);
  470|       |#elif defined(BOTAN_SIMD_USE_NEON)
  471|       |         m_simd = veorq_u32(m_simd, other.m_simd);
  472|       |#elif defined(BOTAN_SIMD_USE_LSX)
  473|       |         m_simd = __lsx_vxor_v(m_simd, other.m_simd);
  474|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  475|       |         m_simd = wasm_v128_xor(m_simd, other.m_simd);
  476|       |#endif
  477|  5.16M|      }
_ZN5Botan9SIMD_4x32C2Ev:
   86|   215k|      BOTAN_FN_ISA_SIMD_4X32 SIMD_4x32() noexcept {
   87|   215k|#if defined(BOTAN_SIMD_USE_SSSE3)
   88|   215k|         m_simd = _mm_setzero_si128();
   89|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
   90|       |         m_simd = vec_splat_u32(0);
   91|       |#elif defined(BOTAN_SIMD_USE_NEON)
   92|       |         m_simd = vdupq_n_u32(0);
   93|       |#elif defined(BOTAN_SIMD_USE_LSX)
   94|       |         m_simd = __lsx_vldi(0);
   95|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
   96|       |         m_simd = wasm_u32x4_const_splat(0);
   97|       |#endif
   98|   215k|      }
_ZN5Botan9SIMD_4x32C2Ejjjj:
  103|  1.29M|      BOTAN_FN_ISA_SIMD_4X32 SIMD_4x32(uint32_t B0, uint32_t B1, uint32_t B2, uint32_t B3) noexcept {
  104|  1.29M|#if defined(BOTAN_SIMD_USE_SSSE3)
  105|  1.29M|         m_simd = _mm_set_epi32(B3, B2, B1, B0);
  106|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  107|       |         __vector unsigned int val = {B0, B1, B2, B3};
  108|       |         m_simd = val;
  109|       |#elif defined(BOTAN_SIMD_USE_NEON)
  110|       |         // Better way to do this?
  111|       |         const uint32_t B[4] = {B0, B1, B2, B3};
  112|       |         m_simd = vld1q_u32(B);
  113|       |#elif defined(BOTAN_SIMD_USE_LSX)
  114|       |         // Better way to do this?
  115|       |         const uint32_t B[4] = {B0, B1, B2, B3};
  116|       |         m_simd = __lsx_vld(B, 0);
  117|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  118|       |         m_simd = wasm_u32x4_make(B0, B1, B2, B3);
  119|       |#endif
  120|  1.29M|      }
_ZNK5Botan9SIMD_4x32eoERKS0_:
  413|  3.22M|      SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 operator^(const SIMD_4x32& other) const noexcept {
  414|  3.22M|         SIMD_4x32 retval(*this);
  415|  3.22M|         retval ^= other;
  416|  3.22M|         return retval;
  417|  3.22M|      }
_ZN5Botan9SIMD_4x3212byte_shuffleERKS0_S2_:
  835|  1.29M|      static inline SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 byte_shuffle(const SIMD_4x32& tbl, const SIMD_4x32& idx) {
  836|  1.29M|#if defined(BOTAN_SIMD_USE_SSSE3)
  837|  1.29M|         return SIMD_4x32(_mm_shuffle_epi8(tbl.raw(), idx.raw()));
  838|       |#elif defined(BOTAN_SIMD_USE_NEON)
  839|       |         const uint8x16_t tbl8 = vreinterpretq_u8_u32(tbl.raw());
  840|       |         const uint8x16_t idx8 = vreinterpretq_u8_u32(idx.raw());
  841|       |
  842|       |   #if defined(BOTAN_TARGET_ARCH_IS_ARM32)
  843|       |         const uint8x8x2_t tbl2 = {vget_low_u8(tbl8), vget_high_u8(tbl8)};
  844|       |
  845|       |         return SIMD_4x32(
  846|       |            vreinterpretq_u32_u8(vcombine_u8(vtbl2_u8(tbl2, vget_low_u8(idx8)), vtbl2_u8(tbl2, vget_high_u8(idx8)))));
  847|       |   #else
  848|       |         return SIMD_4x32(vreinterpretq_u32_u8(vqtbl1q_u8(tbl8, idx8)));
  849|       |   #endif
  850|       |
  851|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  852|       |         const auto r = vec_perm(reinterpret_cast<__vector signed char>(tbl.raw()),
  853|       |                                 reinterpret_cast<__vector signed char>(tbl.raw()),
  854|       |                                 reinterpret_cast<__vector unsigned char>(idx.raw()));
  855|       |         return SIMD_4x32(reinterpret_cast<__vector unsigned int>(r));
  856|       |#elif defined(BOTAN_SIMD_USE_LSX)
  857|       |         return SIMD_4x32(__lsx_vshuf_b(tbl.raw(), tbl.raw(), idx.raw()));
  858|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  859|       |         return SIMD_4x32(wasm_i8x16_swizzle(tbl.raw(), idx.raw()));
  860|       |#endif
  861|  1.29M|      }
_ZNK5Botan9SIMD_4x323shlILi14EEES0_vQaagtT_Li0EltT_Li32E:
  512|   645k|      {
  513|   645k|#if defined(BOTAN_SIMD_USE_SSSE3)
  514|   645k|         return SIMD_4x32(_mm_slli_epi32(m_simd, SHIFT));
  515|       |
  516|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  517|       |         const unsigned int s = static_cast<unsigned int>(SHIFT);
  518|       |         const __vector unsigned int shifts = {s, s, s, s};
  519|       |         return SIMD_4x32(vec_sl(m_simd, shifts));
  520|       |#elif defined(BOTAN_SIMD_USE_NEON)
  521|       |         return SIMD_4x32(vshlq_n_u32(m_simd, SHIFT));
  522|       |#elif defined(BOTAN_SIMD_USE_LSX)
  523|       |         return SIMD_4x32(__lsx_vslli_w(m_simd, SHIFT));
  524|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  525|       |         return SIMD_4x32(wasm_i32x4_shl(m_simd, SHIFT));
  526|       |#endif
  527|   645k|      }
_ZNK5Botan9SIMD_4x323shrILi7EEES0_v:
  530|   645k|      SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 shr() const noexcept {
  531|   645k|#if defined(BOTAN_SIMD_USE_SSSE3)
  532|   645k|         return SIMD_4x32(_mm_srli_epi32(m_simd, SHIFT));
  533|       |
  534|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  535|       |         const unsigned int s = static_cast<unsigned int>(SHIFT);
  536|       |         const __vector unsigned int shifts = {s, s, s, s};
  537|       |         return SIMD_4x32(vec_sr(m_simd, shifts));
  538|       |#elif defined(BOTAN_SIMD_USE_NEON)
  539|       |         return SIMD_4x32(vshrq_n_u32(m_simd, SHIFT));
  540|       |#elif defined(BOTAN_SIMD_USE_LSX)
  541|       |         return SIMD_4x32(__lsx_vsrli_w(m_simd, SHIFT));
  542|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  543|       |         return SIMD_4x32(wasm_u32x4_shr(m_simd, SHIFT));
  544|       |#endif
  545|   645k|      }
_ZNK5Botan9SIMD_4x323shrILi3EEES0_v:
  530|   645k|      SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 shr() const noexcept {
  531|   645k|#if defined(BOTAN_SIMD_USE_SSSE3)
  532|   645k|         return SIMD_4x32(_mm_srli_epi32(m_simd, SHIFT));
  533|       |
  534|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  535|       |         const unsigned int s = static_cast<unsigned int>(SHIFT);
  536|       |         const __vector unsigned int shifts = {s, s, s, s};
  537|       |         return SIMD_4x32(vec_sr(m_simd, shifts));
  538|       |#elif defined(BOTAN_SIMD_USE_NEON)
  539|       |         return SIMD_4x32(vshrq_n_u32(m_simd, SHIFT));
  540|       |#elif defined(BOTAN_SIMD_USE_LSX)
  541|       |         return SIMD_4x32(__lsx_vsrli_w(m_simd, SHIFT));
  542|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  543|       |         return SIMD_4x32(wasm_u32x4_shr(m_simd, SHIFT));
  544|       |#endif
  545|   645k|      }
_ZNK5Botan9SIMD_4x323shrILi11EEES0_v:
  530|   645k|      SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 shr() const noexcept {
  531|   645k|#if defined(BOTAN_SIMD_USE_SSSE3)
  532|   645k|         return SIMD_4x32(_mm_srli_epi32(m_simd, SHIFT));
  533|       |
  534|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  535|       |         const unsigned int s = static_cast<unsigned int>(SHIFT);
  536|       |         const __vector unsigned int shifts = {s, s, s, s};
  537|       |         return SIMD_4x32(vec_sr(m_simd, shifts));
  538|       |#elif defined(BOTAN_SIMD_USE_NEON)
  539|       |         return SIMD_4x32(vshrq_n_u32(m_simd, SHIFT));
  540|       |#elif defined(BOTAN_SIMD_USE_LSX)
  541|       |         return SIMD_4x32(__lsx_vsrli_w(m_simd, SHIFT));
  542|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  543|       |         return SIMD_4x32(wasm_u32x4_shr(m_simd, SHIFT));
  544|       |#endif
  545|   645k|      }
_ZNK5Botan9SIMD_4x323shlILi11EEES0_vQaagtT_Li0EltT_Li32E:
  512|   645k|      {
  513|   645k|#if defined(BOTAN_SIMD_USE_SSSE3)
  514|   645k|         return SIMD_4x32(_mm_slli_epi32(m_simd, SHIFT));
  515|       |
  516|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  517|       |         const unsigned int s = static_cast<unsigned int>(SHIFT);
  518|       |         const __vector unsigned int shifts = {s, s, s, s};
  519|       |         return SIMD_4x32(vec_sl(m_simd, shifts));
  520|       |#elif defined(BOTAN_SIMD_USE_NEON)
  521|       |         return SIMD_4x32(vshlq_n_u32(m_simd, SHIFT));
  522|       |#elif defined(BOTAN_SIMD_USE_LSX)
  523|       |         return SIMD_4x32(__lsx_vslli_w(m_simd, SHIFT));
  524|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  525|       |         return SIMD_4x32(wasm_i32x4_shl(m_simd, SHIFT));
  526|       |#endif
  527|   645k|      }
_ZNK5Botan9SIMD_4x323shrILi10EEES0_v:
  530|  1.29M|      SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 shr() const noexcept {
  531|  1.29M|#if defined(BOTAN_SIMD_USE_SSSE3)
  532|  1.29M|         return SIMD_4x32(_mm_srli_epi32(m_simd, SHIFT));
  533|       |
  534|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  535|       |         const unsigned int s = static_cast<unsigned int>(SHIFT);
  536|       |         const __vector unsigned int shifts = {s, s, s, s};
  537|       |         return SIMD_4x32(vec_sr(m_simd, shifts));
  538|       |#elif defined(BOTAN_SIMD_USE_NEON)
  539|       |         return SIMD_4x32(vshrq_n_u32(m_simd, SHIFT));
  540|       |#elif defined(BOTAN_SIMD_USE_LSX)
  541|       |         return SIMD_4x32(__lsx_vsrli_w(m_simd, SHIFT));
  542|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  543|       |         return SIMD_4x32(wasm_u32x4_shr(m_simd, SHIFT));
  544|       |#endif
  545|  1.29M|      }

_ZN5Botan9SIMD_8x325splatEj:
   58|  26.4k|      static SIMD_8x32 splat(uint32_t B) noexcept { return SIMD_8x32(_mm256_set1_epi32(B)); }
_ZN5Botan9SIMD_8x32C2EDv4_x:
  393|   685k|      explicit SIMD_8x32(__m256i x) noexcept : m_avx2(x) {}
_ZN5Botan9SIMD_8x32C2Ejjjjjjjj:
   46|  13.2k|                         uint32_t B7) noexcept {
   47|       |         // NOLINTNEXTLINE(*-prefer-member-initializer)
   48|  13.2k|         m_avx2 = _mm256_set_epi32(B7, B6, B5, B4, B3, B2, B1, B0);
   49|  13.2k|      }
_ZN5Botan9SIMD_8x3210load_be128EPKhS2_:
  111|  4.61k|      static SIMD_8x32 load_be128(const uint8_t in1[], const uint8_t in2[]) noexcept {
  112|  4.61k|         return SIMD_8x32(
  113|  4.61k|                   _mm256_loadu2_m128i(reinterpret_cast<const __m128i*>(in2), reinterpret_cast<const __m128i*>(in1)))
  114|  4.61k|            .bswap();
  115|  4.61k|      }
_ZNK5Botan9SIMD_8x325bswapEv:
  248|  17.8k|      SIMD_8x32 bswap() const noexcept {
  249|  17.8k|         alignas(32) const uint8_t BSWAP_TBL[32] = {3,  2,  1,  0,  7,  6,  5,  4,  11, 10, 9,  8,  15, 14, 13, 12,
  250|  17.8k|                                                    19, 18, 17, 16, 23, 22, 21, 20, 27, 26, 25, 24, 31, 30, 29, 28};
  251|       |
  252|  17.8k|         const __m256i bswap = _mm256_load_si256(reinterpret_cast<const __m256i*>(BSWAP_TBL));
  253|       |
  254|  17.8k|         const __m256i output = _mm256_shuffle_epi8(m_avx2, bswap);
  255|       |
  256|  17.8k|         return SIMD_8x32(output);
  257|  17.8k|      }
_ZNK5Botan9SIMD_8x32plERKS0_:
  174|  84.4k|      SIMD_8x32 operator+(const SIMD_8x32& other) const noexcept {
  175|  84.4k|         SIMD_8x32 retval(*this);
  176|  84.4k|         retval += other;
  177|  84.4k|         return retval;
  178|  84.4k|      }
_ZN5Botan9SIMD_8x32pLERKS0_:
  209|   139k|      void operator+=(const SIMD_8x32& other) { m_avx2 = _mm256_add_epi32(m_avx2, other.m_avx2); }
_ZNK5Botan9SIMD_8x3211store_le128EPjS1_:
  118|  18.4k|      void store_le128(uint32_t out1[], uint32_t out2[]) const noexcept {
  119|  18.4k|         _mm256_storeu2_m128i(reinterpret_cast<__m128i*>(out2), reinterpret_cast<__m128i*>(out1), raw());
  120|  18.4k|      }
_ZNK5Botan9SIMD_8x323rawEv:
  390|   423k|      __m256i BOTAN_FN_ISA_SIMD_8X32 raw() const noexcept { return m_avx2; }
_ZN5Botan9SIMD_8x32eOERKS0_:
  215|   374k|      void operator^=(const SIMD_8x32& other) { m_avx2 = _mm256_xor_si256(m_avx2, other.m_avx2); }
_ZNK5Botan9SIMD_8x324rotlILm1EEES0_vQaagtT_Li0EltT_Li32E:
  128|   105k|      {
  129|       |#if defined(__AVX512VL__)
  130|       |         return SIMD_8x32(_mm256_rol_epi32(m_avx2, ROT));
  131|       |#else
  132|       |         if constexpr(ROT == 8) {
  133|       |            const __m256i shuf_rotl_8 =
  134|       |               _mm256_set_epi64x(0x0e0d0c0f'0a09080b, 0x06050407'02010003, 0x0e0d0c0f'0a09080b, 0x06050407'02010003);
  135|       |
  136|       |            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_8));
  137|       |         } else if constexpr(ROT == 16) {
  138|       |            const __m256i shuf_rotl_16 =
  139|       |               _mm256_set_epi64x(0x0d0c0f0e'09080b0a, 0x05040706'01000302, 0x0d0c0f0e'09080b0a, 0x05040706'01000302);
  140|       |
  141|       |            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_16));
  142|       |         } else if constexpr(ROT == 24) {
  143|       |            const __m256i shuf_rotl_24 =
  144|       |               _mm256_set_epi64x(0x0c0f0e0d'080b0a09, 0x04070605'00030201, 0x0c0f0e0d'080b0a09, 0x04070605'00030201);
  145|       |
  146|       |            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_24));
  147|   105k|         } else {
  148|   105k|            return SIMD_8x32(_mm256_xor_si256(_mm256_slli_epi32(m_avx2, static_cast<int>(ROT)),
  149|   105k|                                              _mm256_srli_epi32(m_avx2, static_cast<int>(32 - ROT))));
  150|   105k|         }
  151|   105k|#endif
  152|   105k|      }
_ZNK5Botan9SIMD_8x324rotlILm2EEES0_vQaagtT_Li0EltT_Li32E:
  128|  52.8k|      {
  129|       |#if defined(__AVX512VL__)
  130|       |         return SIMD_8x32(_mm256_rol_epi32(m_avx2, ROT));
  131|       |#else
  132|       |         if constexpr(ROT == 8) {
  133|       |            const __m256i shuf_rotl_8 =
  134|       |               _mm256_set_epi64x(0x0e0d0c0f'0a09080b, 0x06050407'02010003, 0x0e0d0c0f'0a09080b, 0x06050407'02010003);
  135|       |
  136|       |            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_8));
  137|       |         } else if constexpr(ROT == 16) {
  138|       |            const __m256i shuf_rotl_16 =
  139|       |               _mm256_set_epi64x(0x0d0c0f0e'09080b0a, 0x05040706'01000302, 0x0d0c0f0e'09080b0a, 0x05040706'01000302);
  140|       |
  141|       |            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_16));
  142|       |         } else if constexpr(ROT == 24) {
  143|       |            const __m256i shuf_rotl_24 =
  144|       |               _mm256_set_epi64x(0x0c0f0e0d'080b0a09, 0x04070605'00030201, 0x0c0f0e0d'080b0a09, 0x04070605'00030201);
  145|       |
  146|       |            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_24));
  147|  52.8k|         } else {
  148|  52.8k|            return SIMD_8x32(_mm256_xor_si256(_mm256_slli_epi32(m_avx2, static_cast<int>(ROT)),
  149|  52.8k|                                              _mm256_srli_epi32(m_avx2, static_cast<int>(32 - ROT))));
  150|  52.8k|         }
  151|  52.8k|#endif
  152|  52.8k|      }
_ZN5Botan9SIMD_8x327load_beEPKh:
   81|  13.2k|      static SIMD_8x32 load_be(const uint8_t* in) noexcept { return load_le(in).bswap(); }
_ZN5Botan9SIMD_8x327load_leEPKh:
   61|  13.2k|      static SIMD_8x32 load_le(const uint8_t* in) noexcept {
   62|  13.2k|         return SIMD_8x32(_mm256_loadu_si256(reinterpret_cast<const __m256i*>(in)));
   63|  13.2k|      }
_ZNK5Botan9SIMD_8x328store_leEPj:
   97|  66.0k|      void store_le(uint32_t out[]) const noexcept { _mm256_storeu_si256(reinterpret_cast<__m256i*>(out), m_avx2); }
_ZNK5Botan9SIMD_8x32eoERKS0_:
  188|   122k|      SIMD_8x32 operator^(const SIMD_8x32& other) const noexcept {
  189|   122k|         SIMD_8x32 retval(*this);
  190|   122k|         retval ^= other;
  191|   122k|         return retval;
  192|   122k|      }
_ZN5Botan9SIMD_8x32C2Ev:
   30|  4.61k|      BOTAN_FORCE_INLINE SIMD_8x32() noexcept : m_avx2(_mm256_setzero_si256()) {}
_ZN5Botan9SIMD_8x32C2Ejjjj:
   52|  27.6k|      explicit SIMD_8x32(uint32_t B0, uint32_t B1, uint32_t B2, uint32_t B3) noexcept {
   53|       |         // NOLINTNEXTLINE(*-prefer-member-initializer)
   54|  27.6k|         m_avx2 = _mm256_set_epi32(B3, B2, B1, B0, B3, B2, B1, B0);
   55|  27.6k|      }
_ZN5Botan9SIMD_8x3210load_le128EPKj:
   76|  18.4k|      static SIMD_8x32 load_le128(const uint32_t* in) noexcept {
   77|  18.4k|         return SIMD_8x32(_mm256_broadcastsi128_si256(_mm_loadu_si128(reinterpret_cast<const __m128i*>(in))));
   78|  18.4k|      }
_ZN5Botan9SIMD_8x3212byte_shuffleERKS0_S2_:
  351|  27.6k|      static inline SIMD_8x32 BOTAN_FN_ISA_SIMD_8X32 byte_shuffle(const SIMD_8x32& tbl, const SIMD_8x32& idx) {
  352|  27.6k|         return SIMD_8x32(_mm256_shuffle_epi8(tbl.raw(), idx.raw()));
  353|  27.6k|      }
_ZNK5Botan9SIMD_8x323shlILi14EEES0_v:
  227|  13.8k|      BOTAN_FN_ISA_SIMD_8X32 SIMD_8x32 shl() const noexcept {
  228|  13.8k|         return SIMD_8x32(_mm256_slli_epi32(m_avx2, SHIFT));
  229|  13.8k|      }
_ZNK5Botan9SIMD_8x323shrILi7EEES0_v:
  232|  13.8k|      BOTAN_FN_ISA_SIMD_8X32 SIMD_8x32 shr() const noexcept {
  233|  13.8k|         return SIMD_8x32(_mm256_srli_epi32(m_avx2, SHIFT));
  234|  13.8k|      }
_ZNK5Botan9SIMD_8x323shrILi3EEES0_v:
  232|  13.8k|      BOTAN_FN_ISA_SIMD_8X32 SIMD_8x32 shr() const noexcept {
  233|  13.8k|         return SIMD_8x32(_mm256_srli_epi32(m_avx2, SHIFT));
  234|  13.8k|      }
_ZNK5Botan9SIMD_8x323shrILi11EEES0_v:
  232|  13.8k|      BOTAN_FN_ISA_SIMD_8X32 SIMD_8x32 shr() const noexcept {
  233|  13.8k|         return SIMD_8x32(_mm256_srli_epi32(m_avx2, SHIFT));
  234|  13.8k|      }
_ZNK5Botan9SIMD_8x323shlILi11EEES0_v:
  227|  13.8k|      BOTAN_FN_ISA_SIMD_8X32 SIMD_8x32 shl() const noexcept {
  228|  13.8k|         return SIMD_8x32(_mm256_slli_epi32(m_avx2, SHIFT));
  229|  13.8k|      }
_ZNK5Botan9SIMD_8x323shrILi10EEES0_v:
  232|  27.6k|      BOTAN_FN_ISA_SIMD_8X32 SIMD_8x32 shr() const noexcept {
  233|  27.6k|         return SIMD_8x32(_mm256_srli_epi32(m_avx2, SHIFT));
  234|  27.6k|      }

_ZN5Botan13generalize_toINSt3__17variantIJNS_3TLS15Client_Hello_13ENS3_20Client_Hello_12_ShimENS3_15Server_Hello_13ENS3_20Server_Hello_12_ShimENS3_19Hello_Retry_RequestENS3_20Encrypted_ExtensionsENS3_14Certificate_13ENS3_22Certificate_Request_13ENS3_21Certificate_Verify_13ENS3_11Finished_13EEEEJS4_S5_EEET_NS2_IJDpT0_EEE:
  102|  5.47k|constexpr GeneralVariantT generalize_to(std::variant<SpecialTs...> specific) {
  103|  5.47k|   static_assert(
  104|  5.47k|      is_generalizable_to<GeneralVariantT>(specific),
  105|  5.47k|      "Desired general type must be implicitly constructible by all types of the specialized std::variant<>");
  106|  5.47k|   return std::visit([](auto s) -> GeneralVariantT { return s; }, std::move(specific));
  107|  5.47k|}
_ZZN5Botan13generalize_toINSt3__17variantIJNS_3TLS15Client_Hello_13ENS3_20Client_Hello_12_ShimENS3_15Server_Hello_13ENS3_20Server_Hello_12_ShimENS3_19Hello_Retry_RequestENS3_20Encrypted_ExtensionsENS3_14Certificate_13ENS3_22Certificate_Request_13ENS3_21Certificate_Verify_13ENS3_11Finished_13EEEEJS4_S5_EEET_NS2_IJDpT0_EEEENKUlSF_E_clIS4_EESE_SF_:
  106|    291|   return std::visit([](auto s) -> GeneralVariantT { return s; }, std::move(specific));
_ZZN5Botan13generalize_toINSt3__17variantIJNS_3TLS15Client_Hello_13ENS3_20Client_Hello_12_ShimENS3_15Server_Hello_13ENS3_20Server_Hello_12_ShimENS3_19Hello_Retry_RequestENS3_20Encrypted_ExtensionsENS3_14Certificate_13ENS3_22Certificate_Request_13ENS3_21Certificate_Verify_13ENS3_11Finished_13EEEEJS4_S5_EEET_NS2_IJDpT0_EEEENKUlSF_E_clIS5_EESE_SF_:
  106|  5.18k|   return std::visit([](auto s) -> GeneralVariantT { return s; }, std::move(specific));
_ZN5Botan13generalize_toINSt3__17variantIJNS_3TLS15Client_Hello_13ENS3_20Client_Hello_12_ShimENS3_15Server_Hello_13ENS3_20Server_Hello_12_ShimENS3_19Hello_Retry_RequestENS3_20Encrypted_ExtensionsENS3_14Certificate_13ENS3_22Certificate_Request_13ENS3_21Certificate_Verify_13ENS3_11Finished_13EEEEJS8_S6_S7_EEET_NS2_IJDpT0_EEE:
  102|  4.16k|constexpr GeneralVariantT generalize_to(std::variant<SpecialTs...> specific) {
  103|  4.16k|   static_assert(
  104|  4.16k|      is_generalizable_to<GeneralVariantT>(specific),
  105|  4.16k|      "Desired general type must be implicitly constructible by all types of the specialized std::variant<>");
  106|  4.16k|   return std::visit([](auto s) -> GeneralVariantT { return s; }, std::move(specific));
  107|  4.16k|}
_ZZN5Botan13generalize_toINSt3__17variantIJNS_3TLS15Client_Hello_13ENS3_20Client_Hello_12_ShimENS3_15Server_Hello_13ENS3_20Server_Hello_12_ShimENS3_19Hello_Retry_RequestENS3_20Encrypted_ExtensionsENS3_14Certificate_13ENS3_22Certificate_Request_13ENS3_21Certificate_Verify_13ENS3_11Finished_13EEEEJS8_S6_S7_EEET_NS2_IJDpT0_EEEENKUlSF_E_clIS6_EESE_SF_:
  106|    524|   return std::visit([](auto s) -> GeneralVariantT { return s; }, std::move(specific));
_ZZN5Botan13generalize_toINSt3__17variantIJNS_3TLS15Client_Hello_13ENS3_20Client_Hello_12_ShimENS3_15Server_Hello_13ENS3_20Server_Hello_12_ShimENS3_19Hello_Retry_RequestENS3_20Encrypted_ExtensionsENS3_14Certificate_13ENS3_22Certificate_Request_13ENS3_21Certificate_Verify_13ENS3_11Finished_13EEEEJS8_S6_S7_EEET_NS2_IJDpT0_EEEENKUlSF_E_clIS7_EESE_SF_:
  106|  3.63k|   return std::visit([](auto s) -> GeneralVariantT { return s; }, std::move(specific));

_ZN5Botan3TLS15Handshake_LayerC2ENS0_15Connection_SideE:
   31|  7.70k|            m_peer(whoami == Connection_Side::Server ? Connection_Side::Client : Connection_Side::Server)
  ------------------
  |  Branch (31:20): [True: 0, False: 7.70k]
  ------------------
   32|       |            // RFC 8446 4.4.2
   33|       |            //    If the corresponding certificate type extension
   34|       |            //    ("server_certificate_type" or "client_certificate_type") was not
   35|       |            //    negotiated in EncryptedExtensions, or the X.509 certificate type
   36|       |            //    was negotiated, then each CertificateEntry contains a DER-encoded
   37|       |            //    X.509 certificate.
   38|       |            //
   39|       |            // We need the certificate_type info to parse Certificate messages.
   40|       |            ,
   41|  7.70k|            m_certificate_type(Certificate_Type::X509) {}

_ZNK5Botan3TLS21Client_Hello_Internal10extensionsEv:
   88|  6.11k|      const Extensions& extensions() const { return m_extensions; }
_ZNK5Botan3TLS21Client_Hello_Internal14legacy_versionEv:
   74|    830|      Protocol_Version legacy_version() const { return m_legacy_version; }
_ZNK5Botan3TLS21Client_Hello_Internal12comp_methodsEv:
   82|    675|      const std::vector<uint8_t>& comp_methods() const { return m_comp_methods; }
_ZN5Botan3TLS21Client_Hello_Internal10extensionsEv:
   90|    366|      Extensions& extensions() { return m_extensions; }
_ZNK5Botan3TLS21Server_Hello_Internal14legacy_versionEv:
  132|    590|      Protocol_Version legacy_version() const { return m_legacy_version; }
_ZNK5Botan3TLS21Server_Hello_Internal11comp_methodEv:
  140|    546|      uint8_t comp_method() const { return m_comp_method; }
_ZNK5Botan3TLS21Server_Hello_Internal22is_hello_retry_requestEv:
  142|  1.13k|      bool is_hello_retry_request() const { return m_is_hello_retry_request; }
_ZNK5Botan3TLS21Server_Hello_Internal10extensionsEv:
  144|  8.46k|      const Extensions& extensions() const { return m_extensions; }
_ZN5Botan3TLS21Server_Hello_Internal10extensionsEv:
  146|  1.60k|      Extensions& extensions() { return m_extensions; }

_ZN5Botan3TLS15TLS_Data_ReaderC2EPKcNSt3__14spanIKhLm18446744073709551615EEE:
   27|  95.1k|            m_typename(type), m_buf(buf_in), m_offset(0) {}
_ZN5Botan3TLS15TLS_Data_Reader12get_uint16_tEv:
   71|   153k|      uint16_t get_uint16_t() {
   72|   153k|         assert_at_least(2);
   73|   153k|         const uint16_t result = make_uint16(m_buf[m_offset], m_buf[m_offset + 1]);
   74|   153k|         m_offset += 2;
   75|   153k|         return result;
   76|   153k|      }
_ZNK5Botan3TLS15TLS_Data_Reader11assert_doneEv:
   29|  38.0k|      void assert_done() const {
   30|  38.0k|         if(has_remaining()) {
  ------------------
  |  Branch (30:13): [True: 31, False: 38.0k]
  ------------------
   31|     31|            throw_decode_error("Extra bytes at end of message");
   32|     31|         }
   33|  38.0k|      }
_ZNK5Botan3TLS15TLS_Data_Reader13has_remainingEv:
   39|   124k|      bool has_remaining() const { return (remaining_bytes() > 0); }
_ZNK5Botan3TLS15TLS_Data_Reader15remaining_bytesEv:
   37|   777k|      size_t remaining_bytes() const { return m_buf.size() - m_offset; }
_ZN5Botan3TLS15TLS_Data_Reader9get_rangeIhEENSt3__16vectorIT_NS3_9allocatorIS5_EEEEmmm:
  110|  22.3k|      std::vector<T> get_range(size_t len_bytes, size_t min_elems, size_t max_elems) {
  111|  22.3k|         const size_t num_elems = get_num_elems(len_bytes, sizeof(T), min_elems, max_elems);
  112|       |
  113|  22.3k|         return get_elem<T, std::vector<T>>(num_elems);
  114|  22.3k|      }
_ZN5Botan3TLS15TLS_Data_Reader13get_num_elemsEmmmm:
  148|  37.7k|      size_t get_num_elems(size_t len_bytes, size_t T_size, size_t min_elems, size_t max_elems) {
  149|  37.7k|         const size_t byte_length = get_length_field(len_bytes);
  150|       |
  151|  37.7k|         if(byte_length % T_size != 0) {
  ------------------
  |  Branch (151:13): [True: 13, False: 37.6k]
  ------------------
  152|     13|            throw_decode_error("Size isn't multiple of T");
  153|     13|         }
  154|       |
  155|  37.7k|         const size_t num_elems = byte_length / T_size;
  156|       |
  157|  37.7k|         if(num_elems < min_elems || num_elems > max_elems) {
  ------------------
  |  Branch (157:13): [True: 77, False: 37.6k]
  |  Branch (157:38): [True: 30, False: 37.6k]
  ------------------
  158|     60|            throw_decode_error("Length field outside parameters");
  159|     60|         }
  160|       |
  161|  37.7k|         return num_elems;
  162|  37.7k|      }
_ZN5Botan3TLS15TLS_Data_Reader16get_length_fieldEm:
  134|  47.9k|      size_t get_length_field(size_t len_bytes) {
  135|  47.9k|         assert_at_least(len_bytes);
  136|       |
  137|  47.9k|         if(len_bytes == 1) {
  ------------------
  |  Branch (137:13): [True: 29.6k, False: 18.2k]
  ------------------
  138|  29.6k|            return get_byte();
  139|  29.6k|         } else if(len_bytes == 2) {
  ------------------
  |  Branch (139:20): [True: 15.2k, False: 2.98k]
  ------------------
  140|  15.2k|            return get_uint16_t();
  141|  15.2k|         } else if(len_bytes == 3) {
  ------------------
  |  Branch (141:20): [True: 2.93k, False: 52]
  ------------------
  142|  2.93k|            return get_uint24_t();
  143|  2.93k|         }
  144|       |
  145|     52|         throw_decode_error("Bad length size");
  146|     52|      }
_ZN5Botan3TLS15TLS_Data_Reader8get_byteEv:
   83|   112k|      uint8_t get_byte() {
   84|   112k|         assert_at_least(1);
   85|   112k|         const uint8_t result = m_buf[m_offset];
   86|   112k|         m_offset += 1;
   87|   112k|         return result;
   88|   112k|      }
_ZN5Botan3TLS15TLS_Data_Reader12get_uint24_tEv:
   64|  39.2k|      uint32_t get_uint24_t() {
   65|  39.2k|         assert_at_least(3);
   66|  39.2k|         const uint32_t result = make_uint32(0, m_buf[m_offset], m_buf[m_offset + 1], m_buf[m_offset + 2]);
   67|  39.2k|         m_offset += 3;
   68|  39.2k|         return result;
   69|  39.2k|      }
_ZN5Botan3TLS15TLS_Data_Reader8get_elemIhNSt3__16vectorIhNS3_9allocatorIhEEEEEET0_m:
   91|   127k|      Container get_elem(size_t num_elems) {
   92|   127k|         assert_at_least(num_elems * sizeof(T));
   93|       |
   94|   127k|         Container result(num_elems);
   95|       |
   96|  2.92M|         for(size_t i = 0; i != num_elems; ++i) {
  ------------------
  |  Branch (96:28): [True: 2.79M, False: 127k]
  ------------------
   97|  2.79M|            result[i] = load_be<T>(&m_buf[m_offset], i);
   98|  2.79M|         }
   99|       |
  100|   127k|         m_offset += num_elems * sizeof(T);
  101|       |
  102|   127k|         return result;
  103|   127k|      }
_ZNK5Botan3TLS15TLS_Data_Reader11read_so_farEv:
   35|  81.0k|      size_t read_so_far() const { return m_offset; }
_ZN5Botan3TLS15TLS_Data_Reader13get_remainingEv:
   41|  2.64k|      std::vector<uint8_t> get_remaining() {
   42|  2.64k|         const std::span rest = m_buf.subspan(m_offset);
   43|  2.64k|         return std::vector<uint8_t>(rest.begin(), rest.end());
   44|  2.64k|      }
_ZN5Botan3TLS15TLS_Data_Reader20get_data_read_so_farEv:
   46|  2.65k|      std::vector<uint8_t> get_data_read_so_far() {
   47|  2.65k|         const std::span first = m_buf.first(m_offset);
   48|  2.65k|         return std::vector<uint8_t>(first.begin(), first.end());
   49|  2.65k|      }
_ZN5Botan3TLS15TLS_Data_Reader12discard_nextEm:
   51|  39.8k|      void discard_next(size_t bytes) {
   52|  39.8k|         assert_at_least(bytes);
   53|  39.8k|         m_offset += bytes;
   54|  39.8k|      }
_ZN5Botan3TLS15TLS_Data_Reader12get_uint32_tEv:
   56|  3.05k|      uint32_t get_uint32_t() {
   57|  3.05k|         assert_at_least(4);
   58|  3.05k|         const uint32_t result =
   59|  3.05k|            make_uint32(m_buf[m_offset], m_buf[m_offset + 1], m_buf[m_offset + 2], m_buf[m_offset + 3]);
   60|  3.05k|         m_offset += 4;
   61|  3.05k|         return result;
   62|  3.05k|      }
_ZNK5Botan3TLS15TLS_Data_Reader13peek_uint16_tEv:
   78|    685|      uint16_t peek_uint16_t() const {
   79|    685|         assert_at_least(2);
   80|    685|         return make_uint16(m_buf[m_offset], m_buf[m_offset + 1]);
   81|    685|      }
_ZN5Botan3TLS15TLS_Data_Reader20get_tls_length_valueEm:
  105|  10.1k|      std::vector<uint8_t> get_tls_length_value(size_t len_bytes) {
  106|  10.1k|         return get_fixed<uint8_t>(get_length_field(len_bytes));
  107|  10.1k|      }
_ZN5Botan3TLS15TLS_Data_Reader10get_stringEmmm:
  123|  2.60k|      std::string get_string(size_t len_bytes, size_t min_bytes, size_t max_bytes) {
  124|  2.60k|         std::vector<uint8_t> v = get_range_vector<uint8_t>(len_bytes, min_bytes, max_bytes);
  125|  2.60k|         return bytes_to_string(v);
  126|  2.60k|      }
_ZN5Botan3TLS15TLS_Data_Reader9get_fixedIhEENSt3__16vectorIT_NS3_9allocatorIS5_EEEEm:
  129|  96.2k|      std::vector<T> get_fixed(size_t size) {
  130|  96.2k|         return get_elem<T, std::vector<T>>(size);
  131|  96.2k|      }
_ZN5Botan3TLS15TLS_Data_Reader16get_range_vectorIhEENSt3__16vectorIT_NS3_9allocatorIS5_EEEEmmm:
  117|  8.51k|      std::vector<T> get_range_vector(size_t len_bytes, size_t min_elems, size_t max_elems) {
  118|  8.51k|         const size_t num_elems = get_num_elems(len_bytes, sizeof(T), min_elems, max_elems);
  119|       |
  120|  8.51k|         return get_elem<T, std::vector<T>>(num_elems);
  121|  8.51k|      }
_ZN5Botan3TLS15TLS_Data_Reader16get_range_vectorItEENSt3__16vectorIT_NS3_9allocatorIS5_EEEEmmm:
  117|  5.98k|      std::vector<T> get_range_vector(size_t len_bytes, size_t min_elems, size_t max_elems) {
  118|  5.98k|         const size_t num_elems = get_num_elems(len_bytes, sizeof(T), min_elems, max_elems);
  119|       |
  120|  5.98k|         return get_elem<T, std::vector<T>>(num_elems);
  121|  5.98k|      }
_ZN5Botan3TLS15TLS_Data_Reader8get_elemItNSt3__16vectorItNS3_9allocatorItEEEEEET0_m:
   91|  6.81k|      Container get_elem(size_t num_elems) {
   92|  6.81k|         assert_at_least(num_elems * sizeof(T));
   93|       |
   94|  6.81k|         Container result(num_elems);
   95|       |
   96|  48.6k|         for(size_t i = 0; i != num_elems; ++i) {
  ------------------
  |  Branch (96:28): [True: 41.8k, False: 6.81k]
  ------------------
   97|  41.8k|            result[i] = load_be<T>(&m_buf[m_offset], i);
   98|  41.8k|         }
   99|       |
  100|  6.81k|         m_offset += num_elems * sizeof(T);
  101|       |
  102|  6.81k|         return result;
  103|  6.81k|      }
_ZN5Botan3TLS15TLS_Data_Reader9get_rangeItEENSt3__16vectorIT_NS3_9allocatorIS5_EEEEmmm:
  110|    887|      std::vector<T> get_range(size_t len_bytes, size_t min_elems, size_t max_elems) {
  111|    887|         const size_t num_elems = get_num_elems(len_bytes, sizeof(T), min_elems, max_elems);
  112|       |
  113|    887|         return get_elem<T, std::vector<T>>(num_elems);
  114|    887|      }

_ZN5Botan2CT13value_barrierITkNSt3__117unsigned_integralEhQntsr3stdE7same_asIbT_EEES3_S3_:
   43|  12.8k|constexpr inline T value_barrier(T x) {
   44|  12.8k|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (44:7): [Folded, False: 12.8k]
  ------------------
   45|      0|      return x;
   46|  12.8k|   } else {
   47|  12.8k|#if defined(BOTAN_CT_VALUE_BARRIER_USE_ASM)
   48|       |      /*
   49|       |      * We may want a "stronger" statement such as
   50|       |      *     asm volatile("" : "+r,m"(x) : : "memory);
   51|       |      * (see https://theunixzoo.co.uk/blog/2021-10-14-preventing-optimisations.html)
   52|       |      * however the current approach seems sufficient with current compilers,
   53|       |      * and is minimally damaging with regards to degrading code generation.
   54|       |      */
   55|  12.8k|      asm("" : "+r"(x) : /* no input */);  // NOLINT(*-no-assembler)
   56|  12.8k|      return x;
   57|       |#elif defined(BOTAN_CT_VALUE_BARRIER_USE_VOLATILE)
   58|       |      volatile T vx = x;
   59|       |      return vx;
   60|       |#else
   61|       |      return x;
   62|       |#endif
   63|  12.8k|   }
   64|  12.8k|}
_ZN5Botan2CT13value_barrierITkNSt3__117unsigned_integralEmQntsr3stdE7same_asIbT_EEES3_S3_:
   43|  70.1k|constexpr inline T value_barrier(T x) {
   44|  70.1k|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (44:7): [Folded, False: 70.1k]
  ------------------
   45|      0|      return x;
   46|  70.1k|   } else {
   47|  70.1k|#if defined(BOTAN_CT_VALUE_BARRIER_USE_ASM)
   48|       |      /*
   49|       |      * We may want a "stronger" statement such as
   50|       |      *     asm volatile("" : "+r,m"(x) : : "memory);
   51|       |      * (see https://theunixzoo.co.uk/blog/2021-10-14-preventing-optimisations.html)
   52|       |      * however the current approach seems sufficient with current compilers,
   53|       |      * and is minimally damaging with regards to degrading code generation.
   54|       |      */
   55|  70.1k|      asm("" : "+r"(x) : /* no input */);  // NOLINT(*-no-assembler)
   56|  70.1k|      return x;
   57|       |#elif defined(BOTAN_CT_VALUE_BARRIER_USE_VOLATILE)
   58|       |      volatile T vx = x;
   59|       |      return vx;
   60|       |#else
   61|       |      return x;
   62|       |#endif
   63|  70.1k|   }
   64|  70.1k|}
_ZN5Botan2CT13value_barrierITkNSt3__117unsigned_integralEjQntsr3stdE7same_asIbT_EEES3_S3_:
   43|  16.6k|constexpr inline T value_barrier(T x) {
   44|  16.6k|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (44:7): [Folded, False: 16.6k]
  ------------------
   45|      0|      return x;
   46|  16.6k|   } else {
   47|  16.6k|#if defined(BOTAN_CT_VALUE_BARRIER_USE_ASM)
   48|       |      /*
   49|       |      * We may want a "stronger" statement such as
   50|       |      *     asm volatile("" : "+r,m"(x) : : "memory);
   51|       |      * (see https://theunixzoo.co.uk/blog/2021-10-14-preventing-optimisations.html)
   52|       |      * however the current approach seems sufficient with current compilers,
   53|       |      * and is minimally damaging with regards to degrading code generation.
   54|       |      */
   55|  16.6k|      asm("" : "+r"(x) : /* no input */);  // NOLINT(*-no-assembler)
   56|  16.6k|      return x;
   57|       |#elif defined(BOTAN_CT_VALUE_BARRIER_USE_VOLATILE)
   58|       |      volatile T vx = x;
   59|       |      return vx;
   60|       |#else
   61|       |      return x;
   62|       |#endif
   63|  16.6k|   }
   64|  16.6k|}

_ZNK5Botan14ASN1_BitString5bytesEv:
  206|  9.42k|      std::span<const uint8_t> bytes() const { return std::span{m_bytes}; }
_ZNK5Botan14ASN1_BitString11unused_bitsEv:
  211|  4.71k|      size_t unused_bits() const { return m_unused_bits; }
_ZNK5Botan10BER_Object6is_setEv:
  267|   127k|      bool is_set() const { return m_type_tag != ASN1_Type::NoObject; }
_ZNK5Botan10BER_Object7taggingEv:
  272|  49.1k|      uint32_t tagging() const { return type_tag() | class_tag(); }
_ZNK5Botan10BER_Object8type_tagEv:
  277|  49.1k|      ASN1_Type type_tag() const { return m_type_tag; }
_ZNK5Botan10BER_Object9class_tagEv:
  282|  58.6k|      ASN1_Class class_tag() const { return m_class_tag; }
_ZNK5Botan10BER_Object4typeEv:
  287|  10.9k|      ASN1_Type type() const { return m_type_tag; }
_ZNK5Botan10BER_Object9get_classEv:
  292|  4.19k|      ASN1_Class get_class() const { return m_class_tag; }
_ZNK5Botan10BER_Object4bitsEv:
  298|   109k|      const uint8_t* bits() const { return m_value.data(); }
_ZNK5Botan10BER_Object6lengthEv:
  303|   280k|      size_t length() const { return m_value.size(); }
_ZNK5Botan10BER_Object4dataEv:
  308|  13.3k|      std::span<const uint8_t> data() const { return std::span{m_value}; }
_ZN5Botan10BER_Object12mutable_bitsEm:
  344|  41.1k|      uint8_t* mutable_bits(size_t length) {
  345|  41.1k|         m_value.resize(length);
  346|  41.1k|         return m_value.data();
  347|  41.1k|      }
_ZNK5Botan3OID5emptyEv:
  468|  1.32k|      bool empty() const { return m_id.empty(); }
_ZNK5Botan3OID9has_valueEv:
  474|  1.32k|      bool has_value() const { return !empty(); }
_ZNK5Botan3OIDeqERKS0_:
  510|  1.35k|      bool operator==(const OID& other) const { return m_id == other.m_id; }
_ZNK5Botan3OID14get_componentsEv:
  530|  3.76k|      const std::vector<uint32_t>& get_components() const {
  531|  3.76k|         return m_id;
  532|  3.76k|      }
_ZNK5Botan11ASN1_String5valueEv:
  590|    939|      const std::string& value() const { return m_utf8_str; }
_ZNK5Botan19AlgorithmIdentifier3oidEv:
  688|  6.68k|      const OID& oid() const { return m_oid; }
_ZNK5Botan19AlgorithmIdentifier10parametersEv:
  693|  3.99k|      const std::vector<uint8_t>& parameters() const { return m_parameters; }
_ZNK5Botan19AlgorithmIdentifier20parameters_are_emptyEv:
  715|  6.66k|      bool parameters_are_empty() const { return m_parameters.empty(); }
_ZNK5Botan19AlgorithmIdentifier28parameters_are_null_or_emptyEv:
  720|  6.66k|      bool parameters_are_null_or_empty() const { return parameters_are_empty() || parameters_are_null(); }
  ------------------
  |  Branch (720:58): [True: 6.19k, False: 475]
  |  Branch (720:84): [True: 336, False: 139]
  ------------------
_ZN5BotanorENS_10ASN1_ClassES0_:
   91|  28.4k|inline ASN1_Class operator|(ASN1_Class x, ASN1_Class y) {
   92|  28.4k|   return static_cast<ASN1_Class>(static_cast<uint32_t>(x) | static_cast<uint32_t>(y));
   93|  28.4k|}
_ZN5BotanorENS_9ASN1_TypeENS_10ASN1_ClassE:
   98|  49.1k|inline uint32_t operator|(ASN1_Type x, ASN1_Class y) {
   99|  49.1k|   return static_cast<uint32_t>(x) | static_cast<uint32_t>(y);
  100|  49.1k|}
_ZN5BotanorENS_10ASN1_ClassENS_9ASN1_TypeE:
  105|  7.92k|inline uint32_t operator|(ASN1_Class x, ASN1_Type y) {
  106|  7.92k|   return static_cast<uint32_t>(x) | static_cast<uint32_t>(y);
  107|  7.92k|}
_ZNKSt3__14hashIN5Botan3OIDEEclERKS2_:
  761|  1.32k|      size_t operator()(const Botan::OID& oid) const noexcept { return static_cast<size_t>(oid.hash_code()); }
_ZN5Botan11ASN1_ObjectC2ERKS0_:
  151|    961|      ASN1_Object(const ASN1_Object&) = default;
_ZN5Botan11ASN1_ObjectD2Ev:
  168|  71.5k|      virtual ~ASN1_Object() = default;
_ZN5Botan11ASN1_ObjectC2EOS0_:
  161|  8.17k|      ASN1_Object(ASN1_Object&&) = default;
_ZN5Botan11ASN1_ObjectaSEOS0_:
  166|  5.62k|      ASN1_Object& operator=(ASN1_Object&&) = default;
_ZN5Botan11ASN1_ObjectC2Ev:
  146|  62.4k|      ASN1_Object() = default;
_ZN5Botan19AlgorithmIdentifierC2Ev:
  655|  8.15k|      AlgorithmIdentifier() = default;
_ZN5Botan3OIDC2Ev:
  423|  9.36k|      explicit OID() = default;
_ZN5Botan14ASN1_BitStringC2Ev:
  179|  4.77k|      ASN1_BitString() = default;
_ZN5Botan10BER_ObjectC2Ev:
  239|  85.1k|      BER_Object() = default;
_ZN5Botan10BER_ObjectaSEOS0_:
  259|  11.6k|      BER_Object& operator=(BER_Object&& other) = default;
_ZN5Botan10BER_ObjectC2EOS0_:
  249|  22.5k|      BER_Object(BER_Object&& other) = default;

_ZN5Botan9ASN1_TimeC2Ev:
   42|  4.11k|      ASN1_Time() = default;

_ZN5Botan13ignore_paramsIJPKhmEEEvDpRKT_:
  149|  4.29k|constexpr void ignore_params([[maybe_unused]] const T&... args) {}
_ZN5Botan13ignore_paramsIJPKmmEEEvDpRKT_:
  149|  14.8k|constexpr void ignore_params([[maybe_unused]] const T&... args) {}
_ZN5Botan13ignore_paramsIJjEEEvDpRKT_:
  149|  1.08k|constexpr void ignore_params([[maybe_unused]] const T&... args) {}

_ZN5Botan11BER_Decoder6Limits3DEREv:
   43|  8.51k|            static Limits DER() { return Limits(false, 0, false, DefaultMaxObjectSize, false); }
_ZN5Botan11BER_Decoder6LimitsC2EbmbNSt3__18optionalImEEb:
  134|  8.51k|                  m_allow_ber(allow_ber),
  135|  8.51k|                  m_max_nested_indef(max_nested_indef),
  136|  8.51k|                  m_allow_standalone_eoc(allow_standalone_eoc),
  137|  8.51k|                  m_max_object_size(max_object_size),
  138|  8.51k|                  m_reject_default_value_encoding(reject_default_value_encoding) {}
_ZNK5Botan11BER_Decoder6Limits18allow_ber_encodingEv:
   57|   110k|            bool allow_ber_encoding() const { return m_allow_ber; }
_ZNK5Botan11BER_Decoder6Limits20require_der_encodingEv:
   62|  69.1k|            bool require_der_encoding() const { return !allow_ber_encoding(); }
_ZNK5Botan11BER_Decoder6Limits15max_object_sizeEv:
   81|  41.3k|            std::optional<size_t> max_object_size() const { return m_max_object_size; }
_ZN5Botan11BER_DecoderC2ERKNS_10BER_ObjectENS0_6LimitsE:
  168|     14|            BER_Decoder(obj.data(), limits) {}
_ZNK5Botan11BER_Decoder6limitsEv:
  198|  24.6k|      Limits limits() const { return m_limits; }
_ZN5Botan11BER_Decoder8get_nextERNS_10BER_ObjectE:
  211|  2.73k|      BER_Decoder& get_next(BER_Object& ber) {
  212|  2.73k|         ber = get_next_object();
  213|  2.73k|         return (*this);
  214|  2.73k|      }
_ZN5Botan11BER_Decoder14start_sequenceEv:
  276|  20.6k|      BER_Decoder start_sequence() { return start_cons(ASN1_Type::Sequence, ASN1_Class::Universal); }
_ZN5Botan11BER_Decoder9start_setEv:
  282|    819|      BER_Decoder start_set() { return start_cons(ASN1_Type::Set, ASN1_Class::Universal); }
_ZN5Botan11BER_Decoder6decodeERm:
  361|     13|      BER_Decoder& decode(size_t& out) { return decode(out, ASN1_Type::Integer, ASN1_Class::Universal); }
_ZN5Botan11BER_Decoder6decodeERNS_6BigIntE:
  366|  2.04k|      BER_Decoder& decode(BigInt& out) { return decode(out, ASN1_Type::Integer, ASN1_Class::Universal); }
_ZN5Botan11BER_Decoder9raw_bytesINSt3__19allocatorIhEEEERS0_RNS2_6vectorIhT_EE:
  339|  13.2k|      BER_Decoder& raw_bytes(std::vector<uint8_t, Alloc>& out) {
  340|  13.2k|         out.clear();
  341|  13.2k|         uint8_t buf[64];
  342|  18.6k|         while(const size_t got = this->read_bytes(std::span{buf})) {
  ------------------
  |  Branch (342:29): [True: 5.43k, False: 13.2k]
  ------------------
  343|  5.43k|            out.insert(out.end(), buf, buf + got);
  344|  5.43k|         }
  345|  13.2k|         return (*this);
  346|  13.2k|      }
_ZN5Botan11BER_Decoder30decode_octet_aligned_bitstringINSt3__19allocatorIhEEEERS0_RNS2_6vectorIhT_EENS_9ASN1_TypeENS_10ASN1_ClassE:
  462|  4.77k|                                                  ASN1_Class class_tag = ASN1_Class::Universal) {
  463|  4.77k|         ASN1_BitString bits;
  464|  4.77k|         decode_bitstring(bits, type_tag, class_tag);
  465|       |
  466|  4.77k|         if(bits.unused_bits() != 0) {
  ------------------
  |  Branch (466:13): [True: 5, False: 4.76k]
  ------------------
  467|      5|            throw Decoding_Error("Expected octet-aligned BIT STRING");
  468|      5|         }
  469|       |
  470|  4.76k|         out.assign(bits.bytes().begin(), bits.bytes().end());
  471|  4.76k|         return (*this);
  472|  4.77k|      }
_ZN5Botan11BER_Decoder15decode_optionalImEERS0_RT_NS_9ASN1_TypeENS_10ASN1_ClassERKS3_:
  551|  2.05k|      BER_Decoder& decode_optional(T& out, ASN1_Type type_tag, ASN1_Class class_tag, const T& default_value = T()) {
  552|  2.05k|         std::optional<T> optval;
  553|  2.05k|         this->decode_optional(optval, type_tag, class_tag);
  554|  2.05k|         out = optval ? *optval : default_value;
  ------------------
  |  Branch (554:16): [True: 6, False: 2.05k]
  ------------------
  555|  2.05k|         return (*this);
  556|  2.05k|      }
_ZN5Botan11BER_Decoder15decode_optionalImEERS0_RNSt3__18optionalIT_EENS_9ASN1_TypeENS_10ASN1_ClassE:
  827|  2.05k|BER_Decoder& BER_Decoder::decode_optional(std::optional<T>& optval, ASN1_Type type_tag, ASN1_Class class_tag) {
  828|  2.05k|   BER_Object obj = get_next_object();
  829|       |
  830|  2.05k|   if(obj.is_a(type_tag, class_tag)) {
  ------------------
  |  Branch (830:7): [True: 13, False: 2.04k]
  ------------------
  831|     13|      T out{};
  832|     13|      if(class_tag == ASN1_Class::ExplicitContextSpecific) {
  ------------------
  |  Branch (832:10): [True: 13, False: 0]
  ------------------
  833|     13|         BER_Decoder(obj, m_limits).decode(out).verify_end();
  834|     13|      } else {
  835|      0|         this->push_back(std::move(obj));
  836|       |         if constexpr(std::is_base_of_v<ASN1_Object, T>) {
  837|       |            // Object types check the tag in decode_from; a re-tagging
  838|       |            // implicit override of an object is not supported here
  839|       |            this->decode(out);
  840|      0|         } else {
  841|      0|            this->decode(out, type_tag, class_tag);
  842|      0|         }
  843|      0|      }
  844|     13|      optval = std::move(out);
  845|  2.04k|   } else {
  846|  2.04k|      this->push_back(std::move(obj));
  847|  2.04k|      optval = std::nullopt;
  848|  2.04k|   }
  849|       |
  850|  2.05k|   return (*this);
  851|  2.05k|}
_ZN5Botan11BER_Decoder22decode_optional_stringINSt3__19allocatorIhEEEERS0_RNS2_6vectorIhT_EENS_9ASN1_TypeEjNS_10ASN1_ClassE:
  722|  2.73k|                                          ASN1_Class class_tag = ASN1_Class::ContextSpecific) {
  723|  2.73k|         BER_Object obj = get_next_object();
  724|       |
  725|  2.73k|         const ASN1_Type type_tag = static_cast<ASN1_Type>(expected_tag);
  726|       |
  727|  2.73k|         if(obj.is_a(type_tag, class_tag)) {
  ------------------
  |  Branch (727:13): [True: 16, False: 2.71k]
  ------------------
  728|     16|            if(class_tag == ASN1_Class::ExplicitContextSpecific) {
  ------------------
  |  Branch (728:16): [True: 0, False: 16]
  ------------------
  729|      0|               BER_Decoder(obj, m_limits).decode(out, real_type).verify_end();
  730|     16|            } else {
  731|     16|               push_back(std::move(obj));
  732|     16|               decode(out, real_type, type_tag, class_tag);
  733|     16|            }
  734|  2.71k|         } else {
  735|  2.71k|            out.clear();
  736|  2.71k|            push_back(std::move(obj));
  737|  2.71k|         }
  738|       |
  739|  2.73k|         return (*this);
  740|  2.73k|      }

_ZN5Botan6BigIntD2Ev:
  185|  5.16k|      ~BigInt() { _const_time_unpoison(); }
_ZN5Botan6BigIntaSEOS0_:
  190|  1.97k|      BigInt& operator=(BigInt&& other) noexcept {
  191|  1.97k|         if(this != &other) {
  ------------------
  |  Branch (191:13): [True: 1.97k, False: 0]
  ------------------
  192|  1.97k|            this->swap(other);
  193|  1.97k|         }
  194|       |
  195|  1.97k|         return (*this);
  196|  1.97k|      }
_ZN5Botan6BigInt4swapERS0_:
  207|  1.97k|      void swap(BigInt& other) noexcept {
  208|  1.97k|         m_data.swap(other.m_data);
  209|  1.97k|         std::swap(m_signedness, other.m_signedness);
  210|  1.97k|      }
_ZN5Botan6BigInt5clearEv:
  441|  3.10k|      void clear() {
  442|  3.10k|         m_data.set_to_zero();
  443|  3.10k|         m_signedness = Positive;
  444|  3.10k|      }
_ZNK5Botan6BigInt6signumEv:
  493|  3.80k|      int signum() const {
  494|  3.80k|         if(sig_words() == 0) {
  ------------------
  |  Branch (494:13): [True: 141, False: 3.66k]
  ------------------
  495|    141|            return 0;
  496|    141|         }
  497|  3.66k|         return (sign() == Negative) ? -1 : 1;
  ------------------
  |  Branch (497:17): [True: 2.62k, False: 1.03k]
  ------------------
  498|  3.80k|      }
_ZNK5Botan6BigInt7is_zeroEv:
  510|  2.43k|      bool is_zero() const { return sig_words() == 0; }
_ZNK5Botan6BigInt7word_atEm:
  601|  9.12k|      word word_at(size_t n) const { return m_data.get_word_at(n); }
_ZNK5Botan6BigInt4signEv:
  641|  3.66k|      Sign sign() const { return (m_signedness); }
_ZN5Botan6BigInt8set_signENS0_4SignE:
  663|  2.43k|      void set_sign(Sign sign) {
  664|  2.43k|         if(sign == Negative && is_zero()) {
  ------------------
  |  Branch (664:13): [True: 2.43k, False: 0]
  |  Branch (664:33): [True: 0, False: 2.43k]
  ------------------
  665|      0|            sign = Positive;
  666|      0|         }
  667|       |
  668|  2.43k|         m_signedness = sign;
  669|  2.43k|      }
_ZNK5Botan6BigInt9sig_wordsEv:
  687|  18.7k|      size_t sig_words() const { return m_data.sig_words(); }
_ZNK5Botan6BigInt5_dataEv:
 1033|    649|      const word* _data() const { return m_data.const_data(); }
_ZN5Botan6BigInt18_assign_from_bytesENSt3__14spanIKhLm18446744073709551615EEE:
 1044|  3.10k|      void _assign_from_bytes(std::span<const uint8_t> bytes) { assign_from_bytes(bytes); }
_ZNK5Botan6BigInt4Data10const_dataEv:
 1088|  5.81k|            const word* const_data() const { return m_reg.data(); }
_ZNK5Botan6BigInt4Data11get_word_atEm:
 1099|  9.12k|            word get_word_at(size_t n) const {
 1100|  9.12k|               if(n < m_reg.size()) {
  ------------------
  |  Branch (1100:19): [True: 9.12k, False: 2]
  ------------------
 1101|  9.12k|                  return m_reg[n];
 1102|  9.12k|               }
 1103|      2|               return 0;
 1104|  9.12k|            }
_ZNK5Botan6BigInt4Data4sizeEv:
 1136|  5.16k|            size_t size() const { return m_reg.size(); }
_ZN5Botan6BigInt4Data4swapERS1_:
 1151|  1.97k|            void swap(Data& other) noexcept {
 1152|  1.97k|               m_reg.swap(other.m_reg);
 1153|  1.97k|               std::swap(m_sig_words, other.m_sig_words);
 1154|  1.97k|            }
_ZN5Botan6BigInt4Data4swapERNSt3__16vectorImNS_16secure_allocatorImEEEE:
 1156|  3.10k|            void swap(secure_vector<word>& reg) noexcept {
 1157|  3.10k|               m_reg.swap(reg);
 1158|  3.10k|               invalidate_sig_words();
 1159|  3.10k|            }
_ZNK5Botan6BigInt4Data20invalidate_sig_wordsEv:
 1161|  3.10k|            void invalidate_sig_words() const noexcept { m_sig_words = sig_words_npos; }
_ZNK5Botan6BigInt4Data9sig_wordsEv:
 1163|  18.7k|            size_t sig_words() const {
 1164|  18.7k|               if(m_sig_words == sig_words_npos) {
  ------------------
  |  Branch (1164:19): [True: 3.10k, False: 15.6k]
  ------------------
 1165|  3.10k|                  m_sig_words = calc_sig_words();
 1166|  3.10k|               }
 1167|  18.7k|               return m_sig_words;
 1168|  18.7k|            }
_ZN5BotaneqERKNS_6BigIntEm:
 1373|  1.96k|inline bool operator==(const BigInt& a, word b) {
 1374|  1.96k|   return (a.cmp_word(b) == 0);
 1375|  1.96k|}
_ZNK5Botan6BigInt9serializeINSt3__16vectorIhNS2_9allocatorIhEEEEEET_m:
  790|  2.95k|      T serialize(size_t len) const {
  791|       |         // TODO this supports std::vector and secure_vector
  792|       |         // it would be nice if this also could work with std::array as in
  793|       |         //   bn.serialize_to<std::array<uint8_t, 32>>(32);
  794|  2.95k|         T out(len);
  795|  2.95k|         this->serialize_to(out);
  796|  2.95k|         return out;
  797|  2.95k|      }
_ZN5Botan6BigIntC2Ev:
   45|  5.16k|      BigInt() = default;
_ZNK5Botan6BigInt9serializeINSt3__16vectorIhNS2_9allocatorIhEEEEEET_v:
  803|  1.12k|      T serialize() const {
  804|  1.12k|         return serialize<T>(this->bytes());
  805|  1.12k|      }

_ZN5Botan20Buffered_Computation6updateEPKhm:
   35|  28.9k|      void update(const uint8_t in[], size_t length) { add_data({in, length}); }
_ZN5Botan20Buffered_Computation6updateENSt3__14spanIKhLm18446744073709551615EEE:
   41|  15.8k|      void update(std::span<const uint8_t> in) { add_data(in); }
_ZN5Botan20Buffered_Computation12final_stdvecEv:
  114|  35.5k|      std::vector<uint8_t> final_stdvec() { return final<std::vector<uint8_t>>(); }
_ZN5Botan20Buffered_Computation5finalITkNS_8concepts21resizable_byte_bufferENSt3__16vectorIhNS3_9allocatorIhEEEEEET_v:
  104|  35.5k|      T final() {
  105|  35.5k|         T output(output_length());
  106|  35.5k|         final_result(output);
  107|  35.5k|         return output;
  108|  35.5k|      }
_ZN5Botan20Buffered_ComputationD2Ev:
  169|  40.6k|      virtual ~Buffered_Computation() = default;

_ZN5Botan17DataSource_MemoryC2ERKNSt3__16vectorIhNS1_9allocatorIhEEEE:
  192|  1.32k|      explicit DataSource_Memory(const std::vector<uint8_t>& in) : DataSource_Memory(std::span<const uint8_t>(in)) {}
_ZN5Botan17DataSource_MemoryC2ENSt3__14spanIKhLm18446744073709551615EEE:
  181|  12.9k|      explicit DataSource_Memory(std::span<const uint8_t> in) : m_offset(0) {
  182|       |         // Guard against forming a range from a null pointer (eg an empty span)
  183|  12.9k|         if(!in.empty()) {
  ------------------
  |  Branch (183:13): [True: 9.45k, False: 3.45k]
  ------------------
  184|  9.45k|            m_source.assign(in.begin(), in.end());
  185|  9.45k|         }
  186|  12.9k|      }
_ZN5Botan10DataSourceC2Ev:
  107|  34.6k|      DataSource() = default;
_ZN5Botan10DataSourceD2Ev:
  109|  33.4k|      virtual ~DataSource() = default;
_ZN5Botan17DataSource_MemoryC2ENSt3__16vectorIhNS_16secure_allocatorIhEEEE:
  175|     37|      explicit DataSource_Memory(secure_vector<uint8_t> in) : m_source(std::move(in)), m_offset(0) {}

_ZN5Botan11DER_Encoder12DER_SequenceD2Ev:
  504|  13.2k|            ~DER_Sequence() = default;
_ZN5Botan11DER_Encoder14start_sequenceEv:
   86|  3.96k|      DER_Encoder& start_sequence() { return start_cons(ASN1_Type::Sequence, ASN1_Class::Universal); }
_ZN5Botan11DER_Encoder9raw_bytesENSt3__14spanIKhLm18446744073709551615EEE:
  154|  2.64k|      DER_Encoder& raw_bytes(std::span<const uint8_t> val) { return raw_bytes(val.data(), val.size()); }
_ZN5Botan11DER_Encoder30encode_octet_aligned_bitstringENSt3__14spanIKhLm18446744073709551615EEENS_9ASN1_TypeENS_10ASN1_ClassE:
  212|  1.32k|                                                  ASN1_Class class_tag = ASN1_Class::Universal) {
  213|  1.32k|         return encode_bitstring(bytes, 0, type_tag, class_tag);
  214|  1.32k|      }
_ZN5Botan11DER_Encoder10add_objectENS_9ASN1_TypeENS_10ASN1_ClassENSt3__14spanIKhLm18446744073709551615EEE:
  410|  3.58k|      DER_Encoder& add_object(ASN1_Type type_tag, ASN1_Class class_tag, std::span<const uint8_t> rep) {
  411|  3.58k|         return add_object(type_tag, class_tag, rep.data(), rep.size());
  412|  3.58k|      }
_ZN5Botan11DER_Encoder10add_objectENS_9ASN1_TypeENS_10ASN1_ClassERKNSt3__16vectorIhNS3_9allocatorIhEEEE:
  421|  2.26k|      DER_Encoder& add_object(ASN1_Type type_tag, ASN1_Class class_tag, const std::vector<uint8_t>& rep) {
  422|  2.26k|         return add_object(type_tag, class_tag, std::span{rep});
  423|  2.26k|      }
_ZN5Botan11DER_Encoder10add_objectENS_9ASN1_TypeENS_10ASN1_ClassERKNSt3__16vectorIhNS_16secure_allocatorIhEEEE:
  432|  1.32k|      DER_Encoder& add_object(ASN1_Type type_tag, ASN1_Class class_tag, const secure_vector<uint8_t>& rep) {
  433|  1.32k|         return add_object(type_tag, class_tag, std::span{rep});
  434|  1.32k|      }
_ZN5Botan11DER_Encoder12DER_SequenceC2EOS1_:
  487|  9.24k|                  m_type_tag(seq.m_type_tag),
  488|  9.24k|                  m_class_tag(seq.m_class_tag),
  489|  9.24k|                  m_sort_contents(seq.m_sort_contents),
  490|  9.24k|                  m_contents(std::move(seq.m_contents)),
  491|  9.24k|                  m_set_contents(std::move(seq.m_set_contents)) {}

_ZNK5Botan9Exception4whatEv:
   94|  7.15k|      const char* what() const noexcept override { return m_msg.c_str(); }

_ZN5Botan10hex_encodeENSt3__14spanIKhLm18446744073709551615EEEb:
   43|  2.64k|inline std::string hex_encode(std::span<const uint8_t> input, bool uppercase = true) {
   44|  2.64k|   return hex_encode(input.data(), input.size(), uppercase);
   45|  2.64k|}

_ZN5Botan11clear_bytesEPvm:
  101|  3.19k|inline constexpr void clear_bytes(void* ptr, size_t bytes) {
  102|  3.19k|   if(bytes > 0) {
  ------------------
  |  Branch (102:7): [True: 88, False: 3.11k]
  ------------------
  103|     88|      std::memset(ptr, 0, bytes);
  104|     88|   }
  105|  3.19k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeERKNSt3__14spanIhLm4EEEjQaaaasr3stdE23is_trivially_copyable_vIT0_Entsr3std6rangesE5rangeIS7_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISF_EESG_E4type10value_typeEEEEvOSC_RKS7_:
  199|   321k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromT& in) {
  200|   321k|   typecast_copy(out, std::span<const FromT, 1>(&in, 1));
  201|   321k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeERKNSt3__14spanIhLm4EEETkNS1_16contiguous_rangeENS3_IKjLm1EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISG_EESH_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS9_IXsr21__is_primary_templateINSA_Iu14__remove_cvrefIDTclL_ZNSC_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSI_ISQ_EESR_E4type10value_typeEEEEvOSN_RKSD_:
  176|   321k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|   321k|   ranges::assert_equal_byte_lengths(out, in);
  178|   321k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|   321k|}
_ZN5Botan13typecast_copyItTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm2EEEQaaaasr3stdE26is_default_constructible_vIT_Esr3stdE23is_trivially_copyable_vIS6_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEEES6_RKSB_:
  210|  43.2k|inline constexpr ToT typecast_copy(const FromR& src) {
  211|  43.2k|   ToT dst;  // NOLINT(*-member-init)
  212|  43.2k|   typecast_copy(dst, src);
  213|  43.2k|   return dst;
  214|  43.2k|}
_ZN5Botan13typecast_copyItTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm2EEEQaaaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIT_Entsr3std6rangesE5rangeISK_EEEvRSK_RKSA_:
  188|  43.2k|inline constexpr void typecast_copy(ToT& out, const FromR& in) {
  189|  43.2k|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|  43.2k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeENSt3__14spanItLm1EEETkNS1_16contiguous_rangeENS3_IKhLm2EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEEEvOSL_RKSB_:
  176|  43.2k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|  43.2k|   ranges::assert_equal_byte_lengths(out, in);
  178|  43.2k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|  43.2k|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm8EEEQaaaasr3stdE26is_default_constructible_vIT_Esr3stdE23is_trivially_copyable_vIS6_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEEES6_RKSB_:
  210|    252|inline constexpr ToT typecast_copy(const FromR& src) {
  211|    252|   ToT dst;  // NOLINT(*-member-init)
  212|    252|   typecast_copy(dst, src);
  213|    252|   return dst;
  214|    252|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm8EEEQaaaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIT_Entsr3std6rangesE5rangeISK_EEEvRSK_RKSA_:
  188|    252|inline constexpr void typecast_copy(ToT& out, const FromR& in) {
  189|    252|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|    252|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeENSt3__14spanImLm1EEETkNS1_16contiguous_rangeENS3_IKhLm8EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEEEvOSL_RKSB_:
  176|    252|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|    252|   ranges::assert_equal_byte_lengths(out, in);
  178|    252|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|    252|}
_ZN5Botan8copy_memIhQsr3stdE12is_trivial_vIu7__decayIT_EEEEvPS1_PKS1_m:
  144|   207k|inline constexpr void copy_mem(T* out, const T* in, size_t n) {
  145|   207k|   BOTAN_ASSERT_IMPLICATION(n > 0, in != nullptr && out != nullptr, "If n > 0 then args are not null");
  ------------------
  |  |  110|   207k|   do {                                                                                          \
  |  |  111|   207k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                              \
  |  |  112|   370k|      if((expr1) && !(expr2)) {                                                                  \
  |  |  ------------------
  |  |  |  Branch (112:10): [True: 185k, False: 21.9k]
  |  |  |  Branch (112:23): [True: 185k, False: 0]
  |  |  |  Branch (112:23): [True: 185k, False: 0]
  |  |  ------------------
  |  |  113|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                                     \
  |  |  114|      0|         Botan::assertion_failure(#expr1 " implies " #expr2, msg, __func__, __FILE__, __LINE__); \
  |  |  115|      0|      }                                                                                          \
  |  |  116|   207k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (116:12): [Folded, False: 207k]
  |  |  ------------------
  ------------------
  146|       |
  147|   207k|   if(in != nullptr && out != nullptr && n > 0) {
  ------------------
  |  Branch (147:7): [True: 203k, False: 3.64k]
  |  Branch (147:24): [True: 199k, False: 4.53k]
  |  Branch (147:42): [True: 185k, False: 13.8k]
  ------------------
  148|   185k|      std::memmove(out, in, sizeof(T) * n);
  149|   185k|   }
  150|   207k|}
_ZN5Botan13typecast_copyIjTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm4EEEQaaaasr3stdE26is_default_constructible_vIT_Esr3stdE23is_trivially_copyable_vIS6_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEEES6_RKSB_:
  210|    182|inline constexpr ToT typecast_copy(const FromR& src) {
  211|    182|   ToT dst;  // NOLINT(*-member-init)
  212|    182|   typecast_copy(dst, src);
  213|    182|   return dst;
  214|    182|}
_ZN5Botan13typecast_copyIjTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm4EEEQaaaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIT_Entsr3std6rangesE5rangeISK_EEEvRSK_RKSA_:
  188|    182|inline constexpr void typecast_copy(ToT& out, const FromR& in) {
  189|    182|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|    182|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeENSt3__14spanIjLm1EEETkNS1_16contiguous_rangeENS3_IKhLm4EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEEEvOSL_RKSB_:
  176|    182|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|    182|   ranges::assert_equal_byte_lengths(out, in);
  178|    182|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|    182|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeERNSt3__15arrayIhLm8EEETkNS1_16contiguous_rangeENS3_ImLm1EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEEEvOSL_RKSB_:
  176|  2.23k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|  2.23k|   ranges::assert_equal_byte_lengths(out, in);
  178|  2.23k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|  2.23k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeERKNSt3__14spanIhLm8EEETkNS1_16contiguous_rangeENS3_IKmLm1EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISG_EESH_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS9_IXsr21__is_primary_templateINSA_Iu14__remove_cvrefIDTclL_ZNSC_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSI_ISQ_EESR_E4type10value_typeEEEEvOSN_RKSD_:
  176|  42.3k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|  42.3k|   ranges::assert_equal_byte_lengths(out, in);
  178|  42.3k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|  42.3k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeERKNSt3__14spanIhLm8EEEmQaaaasr3stdE23is_trivially_copyable_vIT0_Entsr3std6rangesE5rangeIS7_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISF_EESG_E4type10value_typeEEEEvOSC_RKS7_:
  199|  42.3k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromT& in) {
  200|  42.3k|   typecast_copy(out, std::span<const FromT, 1>(&in, 1));
  201|  42.3k|}
_ZN5Botan19secure_scrub_memoryITkNS_6ranges23contiguous_output_rangeERNSt3__16vectorIhNS2_9allocatorIhEEEEEEvOT_:
   59|   107k|void secure_scrub_memory(ranges::contiguous_output_range auto&& data) {
   60|   107k|   secure_scrub_memory(std::ranges::data(data), ranges::size_bytes(data));
   61|   107k|}
_ZN5Botan9clear_memIhEEvPT_m:
  118|     92|inline constexpr void clear_mem(T* ptr, size_t n) {
  119|     92|   clear_bytes(ptr, sizeof(T) * n);
  120|     92|}
_ZN5Botan9clear_memImEEvPT_m:
  118|  3.10k|inline constexpr void clear_mem(T* ptr, size_t n) {
  119|  3.10k|   clear_bytes(ptr, sizeof(T) * n);
  120|  3.10k|}
_ZN5Botan8copy_memITkNS_6ranges23contiguous_output_rangeENSt3__14spanIhLm18446744073709551615EEETkNS1_16contiguous_rangeENS3_IKhLm18446744073709551615EEEQaasr3stdE9is_same_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeENS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIST_EEEvOSB_RKSL_:
  160|  3.08k|inline constexpr void copy_mem(OutR&& out /* NOLINT(*-std-forward) */, const InR& in) {
  161|  3.08k|   ranges::assert_equal_byte_lengths(out, in);
  162|  3.08k|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (162:7): [Folded, False: 3.08k]
  ------------------
  163|      0|      std::copy(std::ranges::begin(in), std::ranges::end(in), std::ranges::begin(out));
  164|  3.08k|   } else if(ranges::size_bytes(out) > 0) {
  ------------------
  |  Branch (164:14): [True: 3.08k, False: 0]
  ------------------
  165|  3.08k|      std::memmove(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  166|  3.08k|   }
  167|  3.08k|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIhLm8EEEQaaaasr3stdE26is_default_constructible_vIT_Esr3stdE23is_trivially_copyable_vIS5_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEEES5_RKSA_:
  210|  3.08k|inline constexpr ToT typecast_copy(const FromR& src) {
  211|  3.08k|   ToT dst;  // NOLINT(*-member-init)
  212|  3.08k|   typecast_copy(dst, src);
  213|  3.08k|   return dst;
  214|  3.08k|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIhLm8EEEQaaaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISC_EESD_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIT_Entsr3std6rangesE5rangeISJ_EEEvRSJ_RKS9_:
  188|  3.08k|inline constexpr void typecast_copy(ToT& out, const FromR& in) {
  189|  3.08k|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|  3.08k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeENSt3__14spanImLm1EEETkNS1_16contiguous_rangeENS3_IhLm8EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS6_IXsr21__is_primary_templateINS7_Iu14__remove_cvrefIDTclL_ZNS9_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSF_ISN_EESO_E4type10value_typeEEEEvOSK_RKSA_:
  176|  3.08k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|  3.08k|   ranges::assert_equal_byte_lengths(out, in);
  178|  3.08k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|  3.08k|}
_ZN5Botan9clear_memIjEEvPT_m:
  118|      6|inline constexpr void clear_mem(T* ptr, size_t n) {
  119|      6|   clear_bytes(ptr, sizeof(T) * n);
  120|      6|}

_ZN5Botan15Key_ConstraintsC2Ev:
  166|  2.05k|      Key_Constraints() : m_value(0) {}

_ZN5Botan18X509_Serial_NumberC2Ev:
   70|  2.05k|      X509_Serial_Number() : m_contents{0x00} {}
_ZNK5Botan7X509_DN8get_bitsEv:
  198|  2.66k|      const std::vector<uint8_t>& get_bits() const { return m_dn_bits; }
_ZNK5Botan7X509_DN16_canonical_bytesEv:
  274|  2.64k|      const std::vector<uint8_t>& _canonical_bytes() const { return m_canonical_dn_bits; }
_ZN5Botan7X509_DNC2Ev:
  159|  5.19k|      X509_DN() = default;
_ZN5Botan10ExtensionsC2Ev:
 1029|  2.05k|      Extensions() = default;
_ZN5Botan15AlternativeNameC2Ev:
  338|  4.11k|      AlternativeName() = default;
_ZN5Botan15NameConstraintsC2Ev:
  755|  2.05k|      NameConstraints() = default;
_ZN5Botan10ExtensionsD2Ev:
 1037|  2.05k|      ~Extensions() override = default;
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension9Key_UsageEEEPKT_RKNS_3OIDE:
  884|  1.32k|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  885|  1.32k|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (885:42): [True: 0, False: 1.32k]
  ------------------
  886|       |            // Unknown_Extension oid_name is empty
  887|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (887:16): [True: 0, False: 0]
  ------------------
  888|      0|               return nullptr;
  889|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (889:32): [True: 0, False: 0]
  ------------------
  890|      0|               return extn_as_T;
  891|      0|            } else {
  892|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  893|      0|            }
  894|      0|         }
  895|       |
  896|  1.32k|         return nullptr;
  897|  1.32k|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension14Subject_Key_IDEEEPKT_RKNS_3OIDE:
  884|  1.32k|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  885|  1.32k|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (885:42): [True: 0, False: 1.32k]
  ------------------
  886|       |            // Unknown_Extension oid_name is empty
  887|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (887:16): [True: 0, False: 0]
  ------------------
  888|      0|               return nullptr;
  889|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (889:32): [True: 0, False: 0]
  ------------------
  890|      0|               return extn_as_T;
  891|      0|            } else {
  892|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  893|      0|            }
  894|      0|         }
  895|       |
  896|  1.32k|         return nullptr;
  897|  1.32k|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension16Authority_Key_IDEEEPKT_RKNS_3OIDE:
  884|  1.32k|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  885|  1.32k|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (885:42): [True: 0, False: 1.32k]
  ------------------
  886|       |            // Unknown_Extension oid_name is empty
  887|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (887:16): [True: 0, False: 0]
  ------------------
  888|      0|               return nullptr;
  889|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (889:32): [True: 0, False: 0]
  ------------------
  890|      0|               return extn_as_T;
  891|      0|            } else {
  892|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  893|      0|            }
  894|      0|         }
  895|       |
  896|  1.32k|         return nullptr;
  897|  1.32k|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension16Name_ConstraintsEEEPKT_RKNS_3OIDE:
  884|  1.32k|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  885|  1.32k|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (885:42): [True: 0, False: 1.32k]
  ------------------
  886|       |            // Unknown_Extension oid_name is empty
  887|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (887:16): [True: 0, False: 0]
  ------------------
  888|      0|               return nullptr;
  889|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (889:32): [True: 0, False: 0]
  ------------------
  890|      0|               return extn_as_T;
  891|      0|            } else {
  892|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  893|      0|            }
  894|      0|         }
  895|       |
  896|  1.32k|         return nullptr;
  897|  1.32k|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension18Extended_Key_UsageEEEPKT_RKNS_3OIDE:
  884|  1.32k|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  885|  1.32k|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (885:42): [True: 0, False: 1.32k]
  ------------------
  886|       |            // Unknown_Extension oid_name is empty
  887|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (887:16): [True: 0, False: 0]
  ------------------
  888|      0|               return nullptr;
  889|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (889:32): [True: 0, False: 0]
  ------------------
  890|      0|               return extn_as_T;
  891|      0|            } else {
  892|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  893|      0|            }
  894|      0|         }
  895|       |
  896|  1.32k|         return nullptr;
  897|  1.32k|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension17Basic_ConstraintsEEEPKT_RKNS_3OIDE:
  884|  1.32k|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  885|  1.32k|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (885:42): [True: 0, False: 1.32k]
  ------------------
  886|       |            // Unknown_Extension oid_name is empty
  887|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (887:16): [True: 0, False: 0]
  ------------------
  888|      0|               return nullptr;
  889|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (889:32): [True: 0, False: 0]
  ------------------
  890|      0|               return extn_as_T;
  891|      0|            } else {
  892|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  893|      0|            }
  894|      0|         }
  895|       |
  896|  1.32k|         return nullptr;
  897|  1.32k|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension23Issuer_Alternative_NameEEEPKT_RKNS_3OIDE:
  884|  1.32k|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  885|  1.32k|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (885:42): [True: 0, False: 1.32k]
  ------------------
  886|       |            // Unknown_Extension oid_name is empty
  887|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (887:16): [True: 0, False: 0]
  ------------------
  888|      0|               return nullptr;
  889|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (889:32): [True: 0, False: 0]
  ------------------
  890|      0|               return extn_as_T;
  891|      0|            } else {
  892|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  893|      0|            }
  894|      0|         }
  895|       |
  896|  1.32k|         return nullptr;
  897|  1.32k|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension24Subject_Alternative_NameEEEPKT_RKNS_3OIDE:
  884|  1.32k|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  885|  1.32k|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (885:42): [True: 0, False: 1.32k]
  ------------------
  886|       |            // Unknown_Extension oid_name is empty
  887|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (887:16): [True: 0, False: 0]
  ------------------
  888|      0|               return nullptr;
  889|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (889:32): [True: 0, False: 0]
  ------------------
  890|      0|               return extn_as_T;
  891|      0|            } else {
  892|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  893|      0|            }
  894|      0|         }
  895|       |
  896|  1.32k|         return nullptr;
  897|  1.32k|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension20Certificate_PoliciesEEEPKT_RKNS_3OIDE:
  884|  1.32k|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  885|  1.32k|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (885:42): [True: 0, False: 1.32k]
  ------------------
  886|       |            // Unknown_Extension oid_name is empty
  887|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (887:16): [True: 0, False: 0]
  ------------------
  888|      0|               return nullptr;
  889|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (889:32): [True: 0, False: 0]
  ------------------
  890|      0|               return extn_as_T;
  891|      0|            } else {
  892|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  893|      0|            }
  894|      0|         }
  895|       |
  896|  1.32k|         return nullptr;
  897|  1.32k|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension28Authority_Information_AccessEEEPKT_RKNS_3OIDE:
  884|  1.32k|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  885|  1.32k|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (885:42): [True: 0, False: 1.32k]
  ------------------
  886|       |            // Unknown_Extension oid_name is empty
  887|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (887:16): [True: 0, False: 0]
  ------------------
  888|      0|               return nullptr;
  889|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (889:32): [True: 0, False: 0]
  ------------------
  890|      0|               return extn_as_T;
  891|      0|            } else {
  892|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  893|      0|            }
  894|      0|         }
  895|       |
  896|  1.32k|         return nullptr;
  897|  1.32k|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension23CRL_Distribution_PointsEEEPKT_RKNS_3OIDE:
  884|  1.32k|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  885|  1.32k|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (885:42): [True: 0, False: 1.32k]
  ------------------
  886|       |            // Unknown_Extension oid_name is empty
  887|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (887:16): [True: 0, False: 0]
  ------------------
  888|      0|               return nullptr;
  889|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (889:32): [True: 0, False: 0]
  ------------------
  890|      0|               return extn_as_T;
  891|      0|            } else {
  892|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  893|      0|            }
  894|      0|         }
  895|       |
  896|  1.32k|         return nullptr;
  897|  1.32k|      }

_ZN5Botan6ranges24assert_exact_byte_lengthILm1ETkNS0_14spanable_rangeENSt3__14spanIKhLm1EEEEEvRKT0_:
   77|  2.79M|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  2.79M|   const std::span s{r};
   79|  2.79M|   if constexpr(statically_spanable_range<R>) {
   80|  2.79M|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  2.79M|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanIhLm18446744073709551615EEETpTkNS0_14spanable_rangeEJNS3_IKhLm18446744073709551615EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  3.08k|{
  101|  3.08k|   const std::span s0{r0};
  102|       |
  103|       |   if constexpr(statically_spanable_range<R0>) {
  104|       |      constexpr size_t expected_size = s0.size_bytes();
  105|       |      (assert_exact_byte_length<expected_size>(rs), ...);
  106|  3.08k|   } else {
  107|  3.08k|      const size_t expected_size = s0.size_bytes();
  108|  3.08k|      const bool correct_size =
  109|  3.08k|         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|  3.08k|      if(!correct_size) {
  ------------------
  |  Branch (111:10): [True: 0, False: 3.08k]
  ------------------
  112|      0|         memory_region_size_violation();
  113|      0|      }
  114|  3.08k|   }
  115|  3.08k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm4ETkNS0_14spanable_rangeENSt3__14spanIhLm4EEEEEvRKT0_:
   77|   642k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|   642k|   const std::span s{r};
   79|   642k|   if constexpr(statically_spanable_range<R>) {
   80|   642k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|   642k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanIhLm4EEETpTkNS0_14spanable_rangeEJNS3_IKjLm1EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|   321k|{
  101|   321k|   const std::span s0{r0};
  102|       |
  103|   321k|   if constexpr(statically_spanable_range<R0>) {
  104|   321k|      constexpr size_t expected_size = s0.size_bytes();
  105|   321k|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|   321k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm4ETkNS0_14spanable_rangeENSt3__14spanIKjLm1EEEEEvRKT0_:
   77|   321k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|   321k|   const std::span s{r};
   79|   321k|   if constexpr(statically_spanable_range<R>) {
   80|   321k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|   321k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanIhLm4EEEEEmRKT_:
   59|   321k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|   321k|   return std::span{r}.size_bytes();
   61|   321k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm2ETkNS0_14spanable_rangeENSt3__14spanIKhLm2EEEEEvRKT0_:
   77|  86.4k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  86.4k|   const std::span s{r};
   79|  86.4k|   if constexpr(statically_spanable_range<R>) {
   80|  86.4k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  86.4k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanItLm1EEETpTkNS0_14spanable_rangeEJNS3_IKhLm2EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  43.2k|{
  101|  43.2k|   const std::span s0{r0};
  102|       |
  103|  43.2k|   if constexpr(statically_spanable_range<R0>) {
  104|  43.2k|      constexpr size_t expected_size = s0.size_bytes();
  105|  43.2k|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|  43.2k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanItLm1EEEEEmRKT_:
   59|  43.2k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  43.2k|   return std::span{r}.size_bytes();
   61|  43.2k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanIhLm18446744073709551615EEEEEmRKT_:
   59|  6.17k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  6.17k|   return std::span{r}.size_bytes();
   61|  6.17k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__14spanIKhLm8EEEEEvRKT0_:
   77|    504|inline constexpr void assert_exact_byte_length(const R& r) {
   78|    504|   const std::span s{r};
   79|    504|   if constexpr(statically_spanable_range<R>) {
   80|    504|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|    504|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanImLm1EEETpTkNS0_14spanable_rangeEJNS3_IKhLm8EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|    252|{
  101|    252|   const std::span s0{r0};
  102|       |
  103|    252|   if constexpr(statically_spanable_range<R0>) {
  104|    252|      constexpr size_t expected_size = s0.size_bytes();
  105|    252|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|    252|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanImLm1EEEEEmRKT_:
   59|  3.34k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  3.34k|   return std::span{r}.size_bytes();
   61|  3.34k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm4ETkNS0_14spanable_rangeENSt3__14spanIKhLm4EEEEEvRKT0_:
   77|    364|inline constexpr void assert_exact_byte_length(const R& r) {
   78|    364|   const std::span s{r};
   79|    364|   if constexpr(statically_spanable_range<R>) {
   80|    364|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|    364|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanIjLm1EEETpTkNS0_14spanable_rangeEJNS3_IKhLm4EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|    182|{
  101|    182|   const std::span s0{r0};
  102|       |
  103|    182|   if constexpr(statically_spanable_range<R0>) {
  104|    182|      constexpr size_t expected_size = s0.size_bytes();
  105|    182|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|    182|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanIjLm1EEEEEmRKT_:
   59|    182|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|    182|   return std::span{r}.size_bytes();
   61|    182|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__15arrayIhLm8EEETpTkNS0_14spanable_rangeEJNS3_ImLm1EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  4.47k|{
  101|  4.47k|   const std::span s0{r0};
  102|       |
  103|  4.47k|   if constexpr(statically_spanable_range<R0>) {
  104|  4.47k|      constexpr size_t expected_size = s0.size_bytes();
  105|  4.47k|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|  4.47k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__15arrayImLm1EEEEEvRKT0_:
   77|  4.47k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  4.47k|   const std::span s{r};
   79|  4.47k|   if constexpr(statically_spanable_range<R>) {
   80|  4.47k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  4.47k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__15arrayIhLm8EEEEEmRKT_:
   59|  2.23k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  2.23k|   return std::span{r}.size_bytes();
   61|  2.23k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__14spanIhLm8EEEEEvRKT0_:
   77|  45.4k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  45.4k|   const std::span s{r};
   79|  45.4k|   if constexpr(statically_spanable_range<R>) {
   80|  45.4k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  45.4k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__14spanIKmLm1EEEEEvRKT0_:
   77|  42.3k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  42.3k|   const std::span s{r};
   79|  42.3k|   if constexpr(statically_spanable_range<R>) {
   80|  42.3k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  42.3k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanIhLm8EEETpTkNS0_14spanable_rangeEJNS3_IKmLm1EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  42.3k|{
  101|  42.3k|   const std::span s0{r0};
  102|       |
  103|  42.3k|   if constexpr(statically_spanable_range<R0>) {
  104|  42.3k|      constexpr size_t expected_size = s0.size_bytes();
  105|  42.3k|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|  42.3k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanIhLm8EEEEEmRKT_:
   59|  42.3k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  42.3k|   return std::span{r}.size_bytes();
   61|  42.3k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__16vectorIhNS2_9allocatorIhEEEEEEmRKT_:
   59|   107k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|   107k|   return std::span{r}.size_bytes();
   61|   107k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanIhLm18446744073709551615EEETpTkNS0_14spanable_rangeEJNS3_IKjLm18446744073709551615EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  42.1k|{
  101|  42.1k|   const std::span s0{r0};
  102|       |
  103|       |   if constexpr(statically_spanable_range<R0>) {
  104|       |      constexpr size_t expected_size = s0.size_bytes();
  105|       |      (assert_exact_byte_length<expected_size>(rs), ...);
  106|  42.1k|   } else {
  107|  42.1k|      const size_t expected_size = s0.size_bytes();
  108|  42.1k|      const bool correct_size =
  109|  42.1k|         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|  42.1k|      if(!correct_size) {
  ------------------
  |  Branch (111:10): [True: 0, False: 42.1k]
  ------------------
  112|      0|         memory_region_size_violation();
  113|      0|      }
  114|  42.1k|   }
  115|  42.1k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__15arrayIhLm8EEEEEvRKT0_:
   77|  3.08k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  3.08k|   const std::span s{r};
   79|  3.08k|   if constexpr(statically_spanable_range<R>) {
   80|  3.08k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  3.08k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanImLm1EEETpTkNS0_14spanable_rangeEJNS3_IhLm8EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  3.08k|{
  101|  3.08k|   const std::span s0{r0};
  102|       |
  103|  3.08k|   if constexpr(statically_spanable_range<R0>) {
  104|  3.08k|      constexpr size_t expected_size = s0.size_bytes();
  105|  3.08k|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|  3.08k|}

_ZN5Botan16secure_allocatorIhE10deallocateEPhm:
  102|  21.2k|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5Botan16secure_allocatorIhE8allocateEm:
   95|  21.2k|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }
_ZN5Botan16secure_allocatorImE10deallocateEPmm:
  102|  3.10k|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5Botan16secure_allocatorImE8allocateEm:
   95|  3.10k|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }
_ZN5BotanpLIhNS_16secure_allocatorIhEEmEERNSt3__16vectorIT_T0_EES8_RKNS3_4pairIPKS5_T1_EE:
  204|  13.2k|std::vector<T, Alloc>& operator+=(std::vector<T, Alloc>& out, const std::pair<const T*, L>& in) {
  205|  13.2k|   if(in.second > 0) {
  ------------------
  |  Branch (205:7): [True: 11.8k, False: 1.32k]
  ------------------
  206|  11.8k|      out.insert(out.end(), in.first, in.first + in.second);
  207|  11.8k|   }
  208|  13.2k|   return out;
  209|  13.2k|}
_ZN5Botan16secure_allocatorIjE10deallocateEPjm:
  102|  40.6k|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5Botan16secure_allocatorIjE8allocateEm:
   95|  40.6k|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }

_ZN5Botan6detail11Strong_BaseINSt3__16vectorIhNS2_9allocatorIhEEEEED2Ev:
  101|  21.5k|      ~Strong_Base() = default;
_ZN5Botan16wrap_strong_typeIhRhQoosr3stdE18constructible_fromIT_T0_Eaasr8conceptsE11strong_typeIS2_Esr3stdE18constructible_fromINS2_12wrapped_typeES3_EEEDcOS3_:
  353|  2.79M|[[nodiscard]] constexpr decltype(auto) wrap_strong_type(ParamT&& t) {
  354|  2.79M|   if constexpr(std::same_as<std::remove_cvref_t<ParamT>, T>) {
  355|       |      // Noop, if the parameter type already is the desired return type.
  356|  2.79M|      return std::forward<ParamT>(t);
  357|       |   } else if constexpr(std::constructible_from<T, ParamT>) {
  358|       |      // Implicit conversion from the parameter type to the return type.
  359|       |      return T{std::forward<ParamT>(t)};
  360|       |   } else {
  361|       |      // Explicitly calling the wrapped type's constructor to support
  362|       |      // implicit conversions on types that mark their constructors as explicit.
  363|       |      static_assert(concepts::strong_type<T> && std::constructible_from<typename T::wrapped_type, ParamT>);
  364|       |      return T{typename T::wrapped_type{std::forward<ParamT>(t)}};
  365|       |   }
  366|  2.79M|}
_ZN5Botan18unwrap_strong_typeIRjEEDcOT_:
  328|   321k|[[nodiscard]] constexpr decltype(auto) unwrap_strong_type(T&& t) {
  329|   321k|   if constexpr(!concepts::strong_type<std::remove_cvref_t<T>>) {
  330|       |      // If the parameter type isn't a strong type, return it as is.
  331|   321k|      return std::forward<T>(t);
  332|       |   } else {
  333|       |      // Unwrap the strong type and return the underlying value.
  334|       |      return std::forward<T>(t).get();
  335|       |   }
  336|   321k|}
_ZN5Botan6detail11Strong_BaseINSt3__16vectorIhNS2_9allocatorIhEEEEEC2Ev:
   85|  10.7k|      Strong_Base() = default;
_ZN5Botan6detail11Strong_BaseINSt3__16vectorIhNS2_9allocatorIhEEEEEC2ES6_:
  105|  10.7k|      constexpr explicit Strong_Base(T v) : m_value(std::move(v)) {}
_ZN5Botan6detail11Strong_BaseINSt3__16vectorIhNS2_9allocatorIhEEEEEaSEOS7_:
   99|  10.7k|      Strong_Base& operator=(Strong_Base&&) noexcept = default;
_ZN5Botan16wrap_strong_typeItRtQoosr3stdE18constructible_fromIT_T0_Eaasr8conceptsE11strong_typeIS2_Esr3stdE18constructible_fromINS2_12wrapped_typeES3_EEEDcOS3_:
  353|  43.2k|[[nodiscard]] constexpr decltype(auto) wrap_strong_type(ParamT&& t) {
  354|  43.2k|   if constexpr(std::same_as<std::remove_cvref_t<ParamT>, T>) {
  355|       |      // Noop, if the parameter type already is the desired return type.
  356|  43.2k|      return std::forward<ParamT>(t);
  357|       |   } else if constexpr(std::constructible_from<T, ParamT>) {
  358|       |      // Implicit conversion from the parameter type to the return type.
  359|       |      return T{std::forward<ParamT>(t)};
  360|       |   } else {
  361|       |      // Explicitly calling the wrapped type's constructor to support
  362|       |      // implicit conversions on types that mark their constructors as explicit.
  363|       |      static_assert(concepts::strong_type<T> && std::constructible_from<typename T::wrapped_type, ParamT>);
  364|       |      return T{typename T::wrapped_type{std::forward<ParamT>(t)}};
  365|       |   }
  366|  43.2k|}
_ZN5Botan18unwrap_strong_typeIRmEEDcOT_:
  328|  42.3k|[[nodiscard]] constexpr decltype(auto) unwrap_strong_type(T&& t) {
  329|  42.3k|   if constexpr(!concepts::strong_type<std::remove_cvref_t<T>>) {
  330|       |      // If the parameter type isn't a strong type, return it as is.
  331|  42.3k|      return std::forward<T>(t);
  332|       |   } else {
  333|       |      // Unwrap the strong type and return the underlying value.
  334|       |      return std::forward<T>(t).get();
  335|       |   }
  336|  42.3k|}
_ZN5Botan16wrap_strong_typeImRmQoosr3stdE18constructible_fromIT_T0_Eaasr8conceptsE11strong_typeIS2_Esr3stdE18constructible_fromINS2_12wrapped_typeES3_EEEDcOS3_:
  353|  3.34k|[[nodiscard]] constexpr decltype(auto) wrap_strong_type(ParamT&& t) {
  354|  3.34k|   if constexpr(std::same_as<std::remove_cvref_t<ParamT>, T>) {
  355|       |      // Noop, if the parameter type already is the desired return type.
  356|  3.34k|      return std::forward<ParamT>(t);
  357|       |   } else if constexpr(std::constructible_from<T, ParamT>) {
  358|       |      // Implicit conversion from the parameter type to the return type.
  359|       |      return T{std::forward<ParamT>(t)};
  360|       |   } else {
  361|       |      // Explicitly calling the wrapped type's constructor to support
  362|       |      // implicit conversions on types that mark their constructors as explicit.
  363|       |      static_assert(concepts::strong_type<T> && std::constructible_from<typename T::wrapped_type, ParamT>);
  364|       |      return T{typename T::wrapped_type{std::forward<ParamT>(t)}};
  365|       |   }
  366|  3.34k|}
_ZN5Botan16wrap_strong_typeIjRjQoosr3stdE18constructible_fromIT_T0_Eaasr8conceptsE11strong_typeIS2_Esr3stdE18constructible_fromINS2_12wrapped_typeES3_EEEDcOS3_:
  353|    182|[[nodiscard]] constexpr decltype(auto) wrap_strong_type(ParamT&& t) {
  354|    182|   if constexpr(std::same_as<std::remove_cvref_t<ParamT>, T>) {
  355|       |      // Noop, if the parameter type already is the desired return type.
  356|    182|      return std::forward<ParamT>(t);
  357|       |   } else if constexpr(std::constructible_from<T, ParamT>) {
  358|       |      // Implicit conversion from the parameter type to the return type.
  359|       |      return T{std::forward<ParamT>(t)};
  360|       |   } else {
  361|       |      // Explicitly calling the wrapped type's constructor to support
  362|       |      // implicit conversions on types that mark their constructors as explicit.
  363|       |      static_assert(concepts::strong_type<T> && std::constructible_from<typename T::wrapped_type, ParamT>);
  364|       |      return T{typename T::wrapped_type{std::forward<ParamT>(t)}};
  365|       |   }
  366|    182|}

_ZN5Botan3TLS12Group_ParamsC2Ev:
  145|  2.15k|      constexpr Group_Params() : m_code(Group_Params_Code::NONE) {}
_ZN5Botan3TLS12Group_ParamsC2Et:
  151|  20.2k|      constexpr Group_Params(uint16_t code) : m_code(static_cast<Group_Params_Code>(code)) {}
_ZNK5Botan3TLS12Group_ParamseqENS0_17Group_Params_CodeE:
  158|    152|      constexpr bool operator==(Group_Params_Code code) const { return m_code == code; }
_ZNK5Botan3TLS12Group_ParamseqES1_:
  160|    587|      constexpr bool operator==(Group_Params other) const { return m_code == other.m_code; }
_ZNK5Botan3TLS12Group_Params9wire_codeEv:
  166|  19.7k|      constexpr uint16_t wire_code() const { return static_cast<uint16_t>(m_code); }

_ZN5Botan3TLS13TLS_ExceptionC2ENS0_9AlertTypeENSt3__117basic_string_viewIcNS3_11char_traitsIcEEEE:
   24|  4.99k|            Exception(err_msg), m_alert_type(type) {}

_ZNK5Botan3TLS9Extension14is_implementedEv:
  113|    111|      virtual bool is_implemented() const { return true; }
_ZN5Botan3TLS21Server_Name_Indicator11static_typeEv:
  123|    868|      static Extension_Code static_type() { return Extension_Code::ServerNameIndication; }
_ZNK5Botan3TLS21Server_Name_Indicator4typeEv:
  125|    868|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS21Server_Name_Indicator5emptyEv:
  135|    697|      bool empty() const override { return false; }
_ZN5Botan3TLS39Application_Layer_Protocol_Notification11static_typeEv:
  148|    597|      static Extension_Code static_type() { return Extension_Code::ApplicationLayerProtocolNegotiation; }
_ZNK5Botan3TLS39Application_Layer_Protocol_Notification4typeEv:
  150|    597|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS39Application_Layer_Protocol_Notification5emptyEv:
  170|    479|      bool empty() const override { return m_protocols.empty(); }
_ZNK5Botan3TLS21Certificate_Type_Base5emptyEv:
  202|    948|      bool empty() const override {
  203|       |         // RFC 7250 4.1
  204|       |         //    If the client has no remaining certificate types to send in the
  205|       |         //    client hello, other than the default X.509 type, it MUST omit the
  206|       |         //    entire client[/server]_certificate_type extension [...].
  207|    948|         return m_from == Connection_Side::Client && m_certificate_types.size() == 1 &&
  ------------------
  |  Branch (207:17): [True: 0, False: 948]
  |  Branch (207:54): [True: 0, False: 0]
  ------------------
  208|      0|                m_certificate_types.front() == Certificate_Type::X509;
  ------------------
  |  Branch (208:17): [True: 0, False: 0]
  ------------------
  209|    948|      }
_ZN5Botan3TLS23Client_Certificate_Type11static_typeEv:
  225|    565|      static Extension_Code static_type() { return Extension_Code::ClientCertificateType; }
_ZNK5Botan3TLS23Client_Certificate_Type4typeEv:
  227|    565|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS23Server_Certificate_Type11static_typeEv:
  239|    671|      static Extension_Code static_type() { return Extension_Code::ServerCertificateType; }
_ZNK5Botan3TLS23Server_Certificate_Type4typeEv:
  241|    671|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS16Supported_Groups11static_typeEv:
  249|  2.59k|      static Extension_Code static_type() { return Extension_Code::SupportedGroups; }
_ZNK5Botan3TLS16Supported_Groups4typeEv:
  251|  1.80k|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS16Supported_Groups5emptyEv:
  267|  1.44k|      bool empty() const override { return m_groups.empty(); }
_ZN5Botan3TLS20Signature_Algorithms11static_typeEv:
  278|  3.39k|      static Extension_Code static_type() { return Extension_Code::SignatureAlgorithms; }
_ZNK5Botan3TLS20Signature_Algorithms4typeEv:
  280|  1.71k|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS20Signature_Algorithms5emptyEv:
  286|  1.38k|      bool empty() const override { return m_schemes.empty(); }
_ZN5Botan3TLS25Signature_Algorithms_Cert11static_typeEv:
  311|    301|      static Extension_Code static_type() { return Extension_Code::CertSignatureAlgorithms; }
_ZNK5Botan3TLS25Signature_Algorithms_Cert4typeEv:
  313|    301|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS25Signature_Algorithms_Cert5emptyEv:
  319|    297|      bool empty() const override { return m_schemes.empty(); }
_ZN5Botan3TLS24SRTP_Protection_Profiles11static_typeEv:
  334|    262|      static Extension_Code static_type() { return Extension_Code::UseSrtp; }
_ZNK5Botan3TLS24SRTP_Protection_Profiles4typeEv:
  336|    262|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS24SRTP_Protection_Profiles5emptyEv:
  342|    261|      bool empty() const override { return m_pp.empty(); }
_ZN5Botan3TLS26Certificate_Status_Request11static_typeEv:
  361|  1.36k|      static Extension_Code static_type() { return Extension_Code::CertificateStatusRequest; }
_ZNK5Botan3TLS26Certificate_Status_Request4typeEv:
  363|  1.36k|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS26Certificate_Status_Request5emptyEv:
  367|    391|      bool empty() const override { return false; }
_ZN5Botan3TLS18Supported_Versions11static_typeEv:
  399|  17.1k|      static Extension_Code static_type() { return Extension_Code::SupportedVersions; }
_ZNK5Botan3TLS18Supported_Versions4typeEv:
  401|  1.14k|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS18Supported_Versions5emptyEv:
  405|    529|      bool empty() const override { return m_versions.empty(); }
_ZNK5Botan3TLS18Supported_Versions8versionsEv:
  415|    540|      const std::vector<Protocol_Version>& versions() const { return m_versions; }
_ZN5Botan3TLS17Record_Size_Limit11static_typeEv:
  430|    592|      static Extension_Code static_type() { return Extension_Code::RecordSizeLimit; }
_ZNK5Botan3TLS17Record_Size_Limit4typeEv:
  432|    592|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS17Record_Size_Limit5emptyEv:
  442|    462|      bool empty() const override { return m_limit == 0; }
_ZNK5Botan3TLS17Unknown_Extension5emptyEv:
  459|  10.8k|      bool empty() const override { return false; }
_ZNK5Botan3TLS17Unknown_Extension4typeEv:
  461|  12.5k|      Extension_Code type() const override { return m_type; }
_ZNK5Botan3TLS17Unknown_Extension14is_implementedEv:
  463|  10.7k|      bool is_implemented() const override { return false; }
_ZNK5Botan3TLS10Extensions42contains_implemented_extensions_other_thanERKNSt3__13setINS0_14Extension_CodeENS2_4lessIS4_EENS2_9allocatorIS4_EEEE:
  516|  7.75k|      bool contains_implemented_extensions_other_than(const std::set<Extension_Code>& allowed_extensions) const {
  517|  7.75k|         return contains_other_than(allowed_extensions, true);
  518|  7.75k|      }
_ZNK5Botan3TLS10Extensions10last_addedEv:
  540|     84|      std::optional<Extension_Code> last_added() const {
  541|     84|         if(m_extension_codes.empty()) {
  ------------------
  |  Branch (541:13): [True: 0, False: 84]
  ------------------
  542|      0|            return {};
  543|     84|         } else {
  544|     84|            return m_extension_codes.back();
  545|     84|         }
  546|     84|      }
_ZN5Botan3TLS10ExtensionsC2Ev:
  548|  22.1k|      Extensions() = default;
_ZNK5Botan3TLS10Extensions3hasINS0_18Supported_VersionsEEEbv:
  483|  14.9k|      bool has() const {
  484|  14.9k|         return get<T>() != nullptr;
  485|  14.9k|      }
_ZNK5Botan3TLS10Extensions3getINS0_18Supported_VersionsEEEPT_v:
  478|  16.0k|      T* get() const {
  479|  16.0k|         return dynamic_cast<T*>(get(T::static_type()));
  480|  16.0k|      }
_ZNK5Botan3TLS10Extensions3getINS0_20Signature_AlgorithmsEEEPT_v:
  478|  1.67k|      T* get() const {
  479|  1.67k|         return dynamic_cast<T*>(get(T::static_type()));
  480|  1.67k|      }
_ZNK5Botan3TLS10Extensions3getINS0_16Supported_GroupsEEEPT_v:
  478|    784|      T* get() const {
  479|    784|         return dynamic_cast<T*>(get(T::static_type()));
  480|    784|      }
_ZNK5Botan3TLS10Extensions3hasINS0_20Signature_AlgorithmsEEEbv:
  483|  1.67k|      bool has() const {
  484|  1.67k|         return get<T>() != nullptr;
  485|  1.67k|      }
_ZN5Botan3TLS10ExtensionsC2EOS1_:
  551|  7.64k|      Extensions(Extensions&&) = default;
_ZN5Botan3TLS9ExtensionD2Ev:
  115|  29.1k|      virtual ~Extension() = default;
_ZNK5Botan3TLS10Extensions3hasINS0_3PSKEEEbv:
  483|  1.01k|      bool has() const {
  484|  1.01k|         return get<T>() != nullptr;
  485|  1.01k|      }
_ZNK5Botan3TLS10Extensions3hasINS0_22PSK_Key_Exchange_ModesEEEbv:
  483|     85|      bool has() const {
  484|     85|         return get<T>() != nullptr;
  485|     85|      }
_ZNK5Botan3TLS10Extensions3getINS0_22PSK_Key_Exchange_ModesEEEPT_v:
  478|     85|      T* get() const {
  479|     85|         return dynamic_cast<T*>(get(T::static_type()));
  480|     85|      }
_ZNK5Botan3TLS10Extensions3hasINS0_16Supported_GroupsEEEbv:
  483|    551|      bool has() const {
  484|    551|         return get<T>() != nullptr;
  485|    551|      }
_ZNK5Botan3TLS10Extensions3hasINS0_9Key_ShareEEEbv:
  483|  1.15k|      bool has() const {
  484|  1.15k|         return get<T>() != nullptr;
  485|  1.15k|      }
_ZNK5Botan3TLS10Extensions3getINS0_9Key_ShareEEEPT_v:
  478|  1.38k|      T* get() const {
  479|  1.38k|         return dynamic_cast<T*>(get(T::static_type()));
  480|  1.38k|      }
_ZNK5Botan3TLS10Extensions3getINS0_3PSKEEEPT_v:
  478|  1.01k|      T* get() const {
  479|  1.01k|         return dynamic_cast<T*>(get(T::static_type()));
  480|  1.01k|      }

_ZN5Botan3TLS23Renegotiation_Extension11static_typeEv:
   31|    320|      static Extension_Code static_type() { return Extension_Code::SafeRenegotiation; }
_ZNK5Botan3TLS23Renegotiation_Extension4typeEv:
   33|    320|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS23Renegotiation_Extension5emptyEv:
   45|     11|      bool empty() const override { return false; }  // always send this
_ZN5Botan3TLS24Session_Ticket_Extension11static_typeEv:
   56|    450|      static Extension_Code static_type() { return Extension_Code::SessionTicket; }
_ZNK5Botan3TLS24Session_Ticket_Extension4typeEv:
   58|    450|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS24Session_Ticket_Extension5emptyEv:
   82|      8|      bool empty() const override { return false; }
_ZN5Botan3TLS23Supported_Point_Formats11static_typeEv:
   99|    269|      static Extension_Code static_type() { return Extension_Code::EcPointFormats; }
_ZNK5Botan3TLS23Supported_Point_Formats4typeEv:
  101|    269|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS23Supported_Point_Formats5emptyEv:
  109|      8|      bool empty() const override { return false; }
_ZN5Botan3TLS22Extended_Master_Secret11static_typeEv:
  122|     92|      static Extension_Code static_type() { return Extension_Code::ExtendedMasterSecret; }
_ZNK5Botan3TLS22Extended_Master_Secret4typeEv:
  124|     92|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS22Extended_Master_Secret5emptyEv:
  128|     11|      bool empty() const override { return false; }
_ZN5Botan3TLS16Encrypt_then_MAC11static_typeEv:
  140|    290|      static Extension_Code static_type() { return Extension_Code::EncryptThenMac; }
_ZNK5Botan3TLS16Encrypt_then_MAC4typeEv:
  142|    290|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS16Encrypt_then_MAC5emptyEv:
  146|     11|      bool empty() const override { return false; }

_ZN5Botan3TLS23Certificate_Authorities11static_typeEv:
   90|    302|      static Extension_Code static_type() { return Extension_Code::CertificateAuthorities; }
_ZN5Botan3TLS6Cookie11static_typeEv:
   44|    208|      static Extension_Code static_type() { return Extension_Code::Cookie; }
_ZNK5Botan3TLS6Cookie4typeEv:
   46|    208|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS6Cookie5emptyEv:
   50|     12|      bool empty() const override { return m_cookie.empty(); }
_ZN5Botan3TLS22PSK_Key_Exchange_Modes11static_typeEv:
   67|    772|      static Extension_Code static_type() { return Extension_Code::PskKeyExchangeModes; }
_ZNK5Botan3TLS22PSK_Key_Exchange_Modes4typeEv:
   69|    687|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS22PSK_Key_Exchange_Modes5emptyEv:
   73|    229|      bool empty() const override { return m_modes.empty(); }
_ZNK5Botan3TLS23Certificate_Authorities4typeEv:
   92|    302|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS23Certificate_Authorities5emptyEv:
   96|      6|      bool empty() const override { return m_distinguished_names.empty(); }
_ZN5Botan3TLS3PSK11static_typeEv:
  112|  2.16k|      static Extension_Code static_type() { return Extension_Code::PresharedKey; }
_ZNK5Botan3TLS3PSK4typeEv:
  114|  1.15k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS9Key_Share11static_typeEv:
  212|  2.83k|      static Extension_Code static_type() { return Extension_Code::KeyShare; }
_ZNK5Botan3TLS9Key_Share4typeEv:
  214|  1.44k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS19EarlyDataIndication11static_typeEv:
  306|    278|      static Extension_Code static_type() { return Extension_Code::EarlyData; }
_ZNK5Botan3TLS19EarlyDataIndication4typeEv:
  308|    278|      Extension_Code type() const override { return static_type(); }

_ZN5Botan3TLS17Handshake_MessageD2Ev:
   54|  89.8k|      virtual ~Handshake_Message() = default;
_ZN5Botan3TLS17Handshake_MessageC2Ev:
   55|  32.7k|      Handshake_Message() = default;
_ZN5Botan3TLS17Handshake_MessageC2EOS1_:
   57|  57.1k|      Handshake_Message(Handshake_Message&&) = default;

_ZN5Botan3TLS8FinishedC2ENSt3__16vectorIhNS2_9allocatorIhEEEE:
  270|  8.62k|      explicit Finished(std::vector<uint8_t> buf) : m_verification_data(std::move(buf)) {}

_ZNK5Botan3TLS20Encrypted_Extensions4typeEv:
  162|  7.14k|      Handshake_Type type() const override { return Handshake_Type::EncryptedExtensions; }

_ZN5Botan3TLS11PskIdentityC2ENSt3__16vectorIhNS2_9allocatorIhEEEEj:
   41|  3.04k|            m_identity(std::move(identity)), m_obfuscated_age(obfuscated_age) {}

_ZN5Botan3TLS16Protocol_VersionC2Ev:
   56|  10.3k|      Protocol_Version() : m_version(0) {}
_ZN5Botan3TLS16Protocol_VersionC2Et:
   58|  41.6k|      explicit Protocol_Version(uint16_t code) : m_version(code) {}
_ZN5Botan3TLS16Protocol_VersionC2ENS0_12Version_CodeE:
   64|  28.0k|            Protocol_Version(static_cast<uint16_t>(named_version)) {}
_ZN5Botan3TLS16Protocol_VersionC2Ehh:
   71|  10.2k|            Protocol_Version(static_cast<uint16_t>((static_cast<uint16_t>(major) << 8) | minor)) {}
_ZNK5Botan3TLS16Protocol_Version13major_versionEv:
   86|  69.0k|      uint8_t major_version() const { return static_cast<uint8_t>(m_version >> 8); }
_ZNK5Botan3TLS16Protocol_Version13minor_versionEv:
   91|    203|      uint8_t minor_version() const { return static_cast<uint8_t>(m_version & 0xFF); }
_ZNK5Botan3TLS16Protocol_VersioneqERKS1_:
  125|  27.5k|      bool operator==(const Protocol_Version& other) const { return (m_version == other.m_version); }
_ZNK5Botan3TLS16Protocol_VersionneERKS1_:
  130|  1.10k|      bool operator!=(const Protocol_Version& other) const { return (m_version != other.m_version); }
_ZNK5Botan3TLS16Protocol_VersiongeERKS1_:
  140|  8.98k|      bool operator>=(const Protocol_Version& other) const { return (*this == other || *this > other); }
  ------------------
  |  Branch (140:70): [True: 2, False: 8.97k]
  |  Branch (140:88): [True: 3.38k, False: 5.59k]
  ------------------
_ZNK5Botan3TLS16Protocol_VersionltERKS1_:
  145|  8.61k|      bool operator<(const Protocol_Version& other) const { return !(*this >= other); }
_ZNK5Botan3TLS16Protocol_VersionleERKS1_:
  150|  15.8k|      bool operator<=(const Protocol_Version& other) const { return (*this == other || *this < other); }
  ------------------
  |  Branch (150:70): [True: 7.20k, False: 8.61k]
  |  Branch (150:88): [True: 5.25k, False: 3.35k]
  ------------------

_ZN5Botan14Cert_Extension9Key_Usage10static_oidEv:
   88|  1.32k|      static OID static_oid() { return OID({2, 5, 29, 15}); }
_ZN5Botan14Cert_Extension14Subject_Key_ID10static_oidEv:
  133|  1.32k|      static OID static_oid() { return OID({2, 5, 29, 14}); }
_ZN5Botan14Cert_Extension16Authority_Key_ID10static_oidEv:
  180|  1.32k|      static OID static_oid() { return OID({2, 5, 29, 35}); }
_ZN5Botan14Cert_Extension16Name_Constraints10static_oidEv:
  311|  1.32k|      static OID static_oid() { return OID({2, 5, 29, 30}); }
_ZN5Botan14Cert_Extension18Extended_Key_Usage10static_oidEv:
  273|  1.32k|      static OID static_oid() { return OID({2, 5, 29, 37}); }
_ZN5Botan14Cert_Extension17Basic_Constraints10static_oidEv:
   57|  1.32k|      static OID static_oid() { return OID({2, 5, 29, 19}); }
_ZN5Botan14Cert_Extension23Issuer_Alternative_Name10static_oidEv:
  235|  1.32k|      static OID static_oid() { return OID({2, 5, 29, 18}); }
_ZN5Botan14Cert_Extension24Subject_Alternative_Name10static_oidEv:
  205|  1.32k|      static OID static_oid() { return OID({2, 5, 29, 17}); }
_ZN5Botan14Cert_Extension21NoRevocationAvailable10static_oidEv:
  834|  1.32k|      static OID static_oid() { return OID({2, 5, 29, 56}); }
_ZN5Botan14Cert_Extension12OCSP_NoCheck10static_oidEv:
  791|  1.32k|      static OID static_oid() { return OID({1, 3, 6, 1, 5, 5, 7, 48, 1, 5}); }
_ZN5Botan14Cert_Extension20Certificate_Policies10static_oidEv:
  343|  1.32k|      static OID static_oid() { return OID({2, 5, 29, 32}); }
_ZN5Botan14Cert_Extension28Authority_Information_Access10static_oidEv:
  468|  1.32k|      static OID static_oid() { return OID({1, 3, 6, 1, 5, 5, 7, 1, 1}); }
_ZN5Botan14Cert_Extension23CRL_Distribution_Points10static_oidEv:
  662|  1.32k|      static OID static_oid() { return OID({2, 5, 29, 31}); }

_ZN5Botan4X5098load_keyERKNSt3__16vectorIhNS1_9allocatorIhEEEE:
   59|  1.32k|inline std::unique_ptr<Public_Key> load_key(const std::vector<uint8_t>& enc) {
   60|  1.32k|   DataSource_Memory source(enc);
   61|  1.32k|   return X509::load_key(source);
   62|  1.32k|}

_ZN5Botan11X509_ObjectC2Ev:
  120|  2.92k|      X509_Object() = default;

LLVMFuzzerInitialize:
   28|      2|extern "C" int LLVMFuzzerInitialize(int* /*argc*/, char*** /*argv*/) {
   29|       |   /*
   30|       |   * This disables the mlock pool, as overwrites within the pool are
   31|       |   * opaque to ASan or other instrumentation.
   32|       |   */
   33|      2|   ::setenv("BOTAN_MLOCK_POOL_SIZE", "0", 1);
   34|      2|   return 0;
   35|      2|}
LLVMFuzzerTestOneInput:
   39|  6.43k|extern "C" int LLVMFuzzerTestOneInput(const uint8_t in[], size_t len) {
   40|  6.43k|   if(len <= max_fuzzer_input_size) {
  ------------------
  |  Branch (40:7): [True: 6.42k, False: 9]
  ------------------
   41|  6.42k|      try {
   42|  6.42k|         fuzz(std::span<const uint8_t>(in, len));
   43|  6.42k|      } catch(const std::exception& e) {
   44|      0|         std::cerr << "Uncaught exception from fuzzer driver " << e.what() << "\n";
   45|      0|         abort();
   46|      0|      } catch(...) {
   47|      0|         std::cerr << "Uncaught exception from fuzzer driver (unknown type)\n";
   48|      0|         abort();
   49|      0|      }
   50|  6.42k|   }
   51|  6.43k|   return 0;
   52|  6.43k|}

_Z4fuzzNSt3__14spanIKhLm18446744073709551615EEE:
   25|  6.42k|void fuzz(std::span<const uint8_t> in) {
   26|  6.42k|   static const Botan::TLS::Default_Policy policy;
   27|       |
   28|  6.42k|   try {
   29|  6.42k|      auto hl1 = prepare(in);
   30|  6.42k|      Botan::TLS::Transcript_Hash_State transcript_hash("SHA-256");
   31|  34.6k|      while(hl1.next_message(policy, transcript_hash).has_value()) {};
  ------------------
  |  Branch (31:13): [True: 28.2k, False: 6.42k]
  ------------------
   32|       |
   33|  6.42k|      auto hl2 = prepare(in);
   34|  6.42k|      while(hl2.next_post_handshake_message(policy).has_value()) {};
  ------------------
  |  Branch (34:13): [True: 0, False: 6.42k]
  ------------------
   35|  6.42k|   } catch(const Botan::Exception& e) {}
   36|  6.42k|}
tls_13_handshake_layer.cpp:_ZN12_GLOBAL__N_17prepareENSt3__14spanIKhLm18446744073709551615EEE:
   17|  7.70k|Botan::TLS::Handshake_Layer prepare(std::span<const uint8_t> data) {
   18|  7.70k|   Botan::TLS::Handshake_Layer hl(Botan::TLS::Connection_Side::Client);
   19|  7.70k|   hl.copy_data(data);
   20|  7.70k|   return hl;
   21|  7.70k|}

_ZNK5Botan19AlgorithmIdentifier19parameters_are_nullEv:
   50|    475|bool AlgorithmIdentifier::parameters_are_null() const {
   51|    475|   return (m_parameters.size() == 2 && (m_parameters[0] == 0x05) && (m_parameters[1] == 0x00));
  ------------------
  |  Branch (51:12): [True: 366, False: 109]
  |  Branch (51:40): [True: 339, False: 27]
  |  Branch (51:69): [True: 336, False: 3]
  ------------------
   52|    475|}
_ZN5BotaneqERKNS_19AlgorithmIdentifierES2_:
   54|  1.35k|bool operator==(const AlgorithmIdentifier& x, const AlgorithmIdentifier& y) {
   55|  1.35k|   return (x.oid() == y.oid() && x.parameters() == y.parameters());
  ------------------
  |  Branch (55:12): [True: 1.33k, False: 21]
  |  Branch (55:34): [True: 1.33k, False: 2]
  ------------------
   56|  1.35k|}
_ZN5BotanneERKNS_19AlgorithmIdentifierES2_:
   58|  1.35k|bool operator!=(const AlgorithmIdentifier& x, const AlgorithmIdentifier& y) {
   59|  1.35k|   return !(x == y);
   60|  1.35k|}
_ZNK5Botan19AlgorithmIdentifier11encode_intoERNS_11DER_EncoderE:
   65|  1.32k|void AlgorithmIdentifier::encode_into(DER_Encoder& codec) const {
   66|  1.32k|   codec.start_sequence().encode(oid()).raw_bytes(parameters()).end_cons();
   67|  1.32k|}
_ZN5Botan19AlgorithmIdentifier11decode_fromERNS_11BER_DecoderE:
   72|  6.97k|void AlgorithmIdentifier::decode_from(BER_Decoder& codec) {
   73|  6.97k|   codec.start_sequence().decode(m_oid).raw_bytes(m_parameters).end_cons();
   74|       |
   75|       |   /*
   76|       |   * The parameters field is OPTIONAL ANY but in practice it is one of
   77|       |   * - empty
   78|       |   * - NULL
   79|       |   * - SEQUENCE
   80|       |   * - OBJECT IDENTIFIER (namedCurve)
   81|       |   * - OCTET STRING (CBC IV in PBES2)
   82|       |   *
   83|       |   * So require it be exactly one of these values. In particular this ensures that
   84|       |   * there is not any additional trailing data (eg after the SEQUENCE encoding)
   85|       |   * that might be otherwise skipped over by a reader.
   86|       |   */
   87|       |
   88|  6.97k|   const bool acceptable_parameters = [&]() {
   89|  6.97k|      if(this->parameters_are_null_or_empty()) {
   90|  6.97k|         return true;
   91|  6.97k|      }
   92|  6.97k|      if(ASN1::is_der_sequence_header(m_parameters)) {
   93|  6.97k|         return true;
   94|  6.97k|      }
   95|  6.97k|      if(ASN1::is_single_der_object(m_parameters, ASN1_Type::ObjectId, ASN1_Class::Universal)) {
   96|  6.97k|         return true;
   97|  6.97k|      }
   98|  6.97k|      if(ASN1::is_single_der_object(m_parameters, ASN1_Type::OctetString, ASN1_Class::Universal)) {
   99|  6.97k|         return true;
  100|  6.97k|      }
  101|  6.97k|      return false;
  102|  6.97k|   }();
  103|       |
  104|  6.97k|   if(!acceptable_parameters) {
  ------------------
  |  Branch (104:7): [True: 112, False: 6.86k]
  ------------------
  105|    112|      throw Decoding_Error("AlgorithmIdentifier parameters were not NULL, a SEQUENCE, an OID, or an OCTET STRING");
  106|    112|   }
  107|  6.97k|}
alg_id.cpp:_ZZN5Botan19AlgorithmIdentifier11decode_fromERNS_11BER_DecoderEENK3$_0clEv:
   88|  6.66k|   const bool acceptable_parameters = [&]() {
   89|  6.66k|      if(this->parameters_are_null_or_empty()) {
  ------------------
  |  Branch (89:10): [True: 6.52k, False: 139]
  ------------------
   90|  6.52k|         return true;
   91|  6.52k|      }
   92|    139|      if(ASN1::is_der_sequence_header(m_parameters)) {
  ------------------
  |  Branch (92:10): [True: 7, False: 132]
  ------------------
   93|      7|         return true;
   94|      7|      }
   95|    132|      if(ASN1::is_single_der_object(m_parameters, ASN1_Type::ObjectId, ASN1_Class::Universal)) {
  ------------------
  |  Branch (95:10): [True: 12, False: 120]
  ------------------
   96|     12|         return true;
   97|     12|      }
   98|    120|      if(ASN1::is_single_der_object(m_parameters, ASN1_Type::OctetString, ASN1_Class::Universal)) {
  ------------------
  |  Branch (98:10): [True: 8, False: 112]
  ------------------
   99|      8|         return true;
  100|      8|      }
  101|    112|      return false;
  102|    120|   }();

_ZNK5Botan11ASN1_Object10BER_encodeEv:
   21|  2.26k|std::vector<uint8_t> ASN1_Object::BER_encode() const {
   22|  2.26k|   std::vector<uint8_t> output;
   23|  2.26k|   DER_Encoder der(output);
   24|  2.26k|   this->encode_into(der);
   25|  2.26k|   return output;
   26|  2.26k|}
_ZN5Botan14ASN1_BitStringC2ENSt3__16vectorIhNS1_9allocatorIhEEEEm:
   29|  4.71k|      m_bytes(std::move(bytes)), m_unused_bits(unused_bits) {
   30|  4.71k|   if(m_unused_bits >= 8) {
  ------------------
  |  Branch (30:7): [True: 0, False: 4.71k]
  ------------------
   31|      0|      throw Invalid_Argument("ASN1_BitString: Invalid unused bit count");
   32|      0|   }
   33|       |
   34|  4.71k|   if(m_bytes.empty() && m_unused_bits != 0) {
  ------------------
  |  Branch (34:7): [True: 284, False: 4.43k]
  |  Branch (34:26): [True: 0, False: 284]
  ------------------
   35|      0|      throw Invalid_Argument("ASN1_BitString: Empty BIT STRING cannot have unused bits");
   36|      0|   }
   37|       |
   38|  4.71k|   if(m_unused_bits > 0 && (m_bytes.back() & ((1U << m_unused_bits) - 1)) != 0) {
  ------------------
  |  Branch (38:7): [True: 5, False: 4.71k]
  |  Branch (38:28): [True: 0, False: 5]
  ------------------
   39|      0|      throw Invalid_Argument("ASN1_BitString: Unused bits must be zero");
   40|      0|   }
   41|  4.71k|}
_ZN5Botan10BER_ObjectD2Ev:
   58|   107k|BER_Object::~BER_Object() {
   59|   107k|   secure_scrub_memory(m_value);
   60|   107k|}
_ZNK5Botan10BER_Object11assert_is_aENS_9ASN1_TypeENS_10ASN1_ClassENSt3__117basic_string_viewIcNS3_11char_traitsIcEEEE:
   65|  29.0k|void BER_Object::assert_is_a(ASN1_Type expected_type_tag, ASN1_Class expected_class_tag, std::string_view descr) const {
   66|  29.0k|   if(!this->is_a(expected_type_tag, expected_class_tag)) {
  ------------------
  |  Branch (66:7): [True: 328, False: 28.7k]
  ------------------
   67|    328|      std::stringstream msg;
   68|       |
   69|    328|      msg << "Tag mismatch when decoding " << descr << " got ";
   70|       |
   71|    328|      if(m_class_tag == ASN1_Class::NoObject && m_type_tag == ASN1_Type::NoObject) {
  ------------------
  |  Branch (71:10): [True: 12, False: 316]
  |  Branch (71:49): [True: 12, False: 0]
  ------------------
   72|     12|         msg << "EOF";
   73|    316|      } else {
   74|    316|         if(m_class_tag == ASN1_Class::Universal || m_class_tag == ASN1_Class::Constructed) {
  ------------------
  |  Branch (74:13): [True: 124, False: 192]
  |  Branch (74:53): [True: 80, False: 112]
  ------------------
   75|    204|            msg << asn1_tag_to_string(m_type_tag);
   76|    204|         } else {
   77|    112|            msg << std::to_string(static_cast<uint32_t>(m_type_tag));
   78|    112|         }
   79|       |
   80|    316|         msg << "/" << asn1_class_to_string(m_class_tag);
   81|    316|      }
   82|       |
   83|    328|      msg << " expected ";
   84|       |
   85|    328|      if(expected_class_tag == ASN1_Class::Universal || expected_class_tag == ASN1_Class::Constructed) {
  ------------------
  |  Branch (85:10): [True: 75, False: 253]
  |  Branch (85:57): [True: 253, False: 0]
  ------------------
   86|    328|         msg << asn1_tag_to_string(expected_type_tag);
   87|    328|      } else {
   88|      0|         msg << std::to_string(static_cast<uint32_t>(expected_type_tag));
   89|      0|      }
   90|       |
   91|    328|      msg << "/" << asn1_class_to_string(expected_class_tag);
   92|       |
   93|    328|      throw BER_Decoding_Error(msg.str());
   94|    328|   }
   95|  29.0k|}
_ZNK5Botan10BER_Object4is_aENS_9ASN1_TypeENS_10ASN1_ClassE:
   97|  35.2k|bool BER_Object::is_a(ASN1_Type expected_type_tag, ASN1_Class expected_class_tag) const {
   98|  35.2k|   return (m_type_tag == expected_type_tag && m_class_tag == expected_class_tag);
  ------------------
  |  Branch (98:12): [True: 28.8k, False: 6.40k]
  |  Branch (98:47): [True: 28.8k, False: 12]
  ------------------
   99|  35.2k|}
_ZNK5Botan10BER_Object4is_aEiNS_10ASN1_ClassE:
  101|  1.32k|bool BER_Object::is_a(int expected_type_tag, ASN1_Class expected_class_tag) const {
  102|  1.32k|   return is_a(ASN1_Type(expected_type_tag), expected_class_tag);
  103|  1.32k|}
_ZN5Botan10BER_Object11set_taggingENS_9ASN1_TypeENS_10ASN1_ClassE:
  105|  45.6k|void BER_Object::set_tagging(ASN1_Type type_tag, ASN1_Class class_tag) {
  106|  45.6k|   m_type_tag = type_tag;
  107|  45.6k|   m_class_tag = class_tag;
  108|  45.6k|}
_ZN5Botan20asn1_class_to_stringENS_10ASN1_ClassE:
  110|    644|std::string asn1_class_to_string(ASN1_Class type) {
  111|    644|   switch(type) {
  112|    199|      case ASN1_Class::Universal:
  ------------------
  |  Branch (112:7): [True: 199, False: 445]
  ------------------
  113|    199|         return "UNIVERSAL";
  114|    333|      case ASN1_Class::Constructed:
  ------------------
  |  Branch (114:7): [True: 333, False: 311]
  ------------------
  115|    333|         return "CONSTRUCTED";
  116|      7|      case ASN1_Class::ContextSpecific:
  ------------------
  |  Branch (116:7): [True: 7, False: 637]
  ------------------
  117|      7|         return "CONTEXT_SPECIFIC";
  118|      2|      case ASN1_Class::Application:
  ------------------
  |  Branch (118:7): [True: 2, False: 642]
  ------------------
  119|      2|         return "APPLICATION";
  120|     20|      case ASN1_Class::Private:
  ------------------
  |  Branch (120:7): [True: 20, False: 624]
  ------------------
  121|     20|         return "PRIVATE";
  122|      0|      case ASN1_Class::NoObject:
  ------------------
  |  Branch (122:7): [True: 0, False: 644]
  ------------------
  123|      0|         return "NO_OBJECT";
  124|     83|      default:
  ------------------
  |  Branch (124:7): [True: 83, False: 561]
  ------------------
  125|     83|         return "CLASS(" + std::to_string(static_cast<size_t>(type)) + ")";
  126|    644|   }
  127|    644|}
_ZN5Botan18asn1_tag_to_stringENS_9ASN1_TypeE:
  129|    598|std::string asn1_tag_to_string(ASN1_Type type) {
  130|    598|   switch(type) {
  131|    246|      case ASN1_Type::Sequence:
  ------------------
  |  Branch (131:7): [True: 246, False: 352]
  ------------------
  132|    246|         return "SEQUENCE";
  133|       |
  134|     19|      case ASN1_Type::Set:
  ------------------
  |  Branch (134:7): [True: 19, False: 579]
  ------------------
  135|     19|         return "SET";
  136|       |
  137|      2|      case ASN1_Type::PrintableString:
  ------------------
  |  Branch (137:7): [True: 2, False: 596]
  ------------------
  138|      2|         return "PRINTABLE STRING";
  139|       |
  140|      1|      case ASN1_Type::NumericString:
  ------------------
  |  Branch (140:7): [True: 1, False: 597]
  ------------------
  141|      1|         return "NUMERIC STRING";
  142|       |
  143|      8|      case ASN1_Type::Ia5String:
  ------------------
  |  Branch (143:7): [True: 8, False: 590]
  ------------------
  144|      8|         return "IA5 STRING";
  145|       |
  146|      3|      case ASN1_Type::TeletexString:
  ------------------
  |  Branch (146:7): [True: 3, False: 595]
  ------------------
  147|      3|         return "T61 STRING";
  148|       |
  149|     60|      case ASN1_Type::Utf8String:
  ------------------
  |  Branch (149:7): [True: 60, False: 538]
  ------------------
  150|     60|         return "UTF8 STRING";
  151|       |
  152|      4|      case ASN1_Type::VisibleString:
  ------------------
  |  Branch (152:7): [True: 4, False: 594]
  ------------------
  153|      4|         return "VISIBLE STRING";
  154|       |
  155|      2|      case ASN1_Type::BmpString:
  ------------------
  |  Branch (155:7): [True: 2, False: 596]
  ------------------
  156|      2|         return "BMP STRING";
  157|       |
  158|      2|      case ASN1_Type::UniversalString:
  ------------------
  |  Branch (158:7): [True: 2, False: 596]
  ------------------
  159|      2|         return "UNIVERSAL STRING";
  160|       |
  161|      1|      case ASN1_Type::UtcTime:
  ------------------
  |  Branch (161:7): [True: 1, False: 597]
  ------------------
  162|      1|         return "UTC TIME";
  163|       |
  164|      3|      case ASN1_Type::GeneralizedTime:
  ------------------
  |  Branch (164:7): [True: 3, False: 595]
  ------------------
  165|      3|         return "GENERALIZED TIME";
  166|       |
  167|      3|      case ASN1_Type::OctetString:
  ------------------
  |  Branch (167:7): [True: 3, False: 595]
  ------------------
  168|      3|         return "OCTET STRING";
  169|       |
  170|      4|      case ASN1_Type::BitString:
  ------------------
  |  Branch (170:7): [True: 4, False: 594]
  ------------------
  171|      4|         return "BIT STRING";
  172|       |
  173|      2|      case ASN1_Type::Enumerated:
  ------------------
  |  Branch (173:7): [True: 2, False: 596]
  ------------------
  174|      2|         return "ENUMERATED";
  175|       |
  176|     77|      case ASN1_Type::Integer:
  ------------------
  |  Branch (176:7): [True: 77, False: 521]
  ------------------
  177|     77|         return "INTEGER";
  178|       |
  179|      3|      case ASN1_Type::Null:
  ------------------
  |  Branch (179:7): [True: 3, False: 595]
  ------------------
  180|      3|         return "NULL";
  181|       |
  182|     11|      case ASN1_Type::ObjectId:
  ------------------
  |  Branch (182:7): [True: 11, False: 587]
  ------------------
  183|     11|         return "OBJECT";
  184|       |
  185|      8|      case ASN1_Type::Boolean:
  ------------------
  |  Branch (185:7): [True: 8, False: 590]
  ------------------
  186|      8|         return "BOOLEAN";
  187|       |
  188|      0|      case ASN1_Type::NoObject:
  ------------------
  |  Branch (188:7): [True: 0, False: 598]
  ------------------
  189|      0|         return "NO_OBJECT";
  190|       |
  191|    139|      default:
  ------------------
  |  Branch (191:7): [True: 139, False: 459]
  ------------------
  192|    139|         return "TAG(" + std::to_string(static_cast<uint32_t>(type)) + ")";
  193|    598|   }
  194|    598|}
_ZN5Botan18BER_Decoding_ErrorC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  199|  1.21k|BER_Decoding_Error::BER_Decoding_Error(std::string_view err) : Decoding_Error(fmt("BER: {}", err)) {}
_ZN5Botan11BER_Bad_TagC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEj:
  201|     59|BER_Bad_Tag::BER_Bad_Tag(std::string_view str, uint32_t tagging) : BER_Decoding_Error(fmt("{}: {}", str, tagging)) {}
_ZN5Botan4ASN115put_in_sequenceERKNSt3__16vectorIhNS1_9allocatorIhEEEE:
  208|  4.00k|std::vector<uint8_t> put_in_sequence(const std::vector<uint8_t>& contents) {
  209|  4.00k|   return ASN1::put_in_sequence(contents.data(), contents.size());
  210|  4.00k|}
_ZN5Botan4ASN115put_in_sequenceEPKhm:
  212|  4.00k|std::vector<uint8_t> put_in_sequence(const uint8_t bits[], size_t len) {
  213|  4.00k|   std::vector<uint8_t> output = der_sequence_header(len);
  214|  4.00k|   output.reserve(output.size() + len);
  215|  4.00k|   if(len > 0) {
  ------------------
  |  Branch (215:7): [True: 1.33k, False: 2.66k]
  ------------------
  216|  1.33k|      output.insert(output.end(), bits, bits + len);
  217|  1.33k|   }
  218|  4.00k|   return output;
  219|  4.00k|}
_ZN5Botan4ASN19to_stringERKNS_10BER_ObjectE:
  224|  3.49k|std::string to_string(const BER_Object& obj) {
  225|  3.49k|   return bytes_to_string(obj.data());
  226|  3.49k|}
_ZN5Botan4ASN19maybe_BERERNS_10DataSourceE:
  231|  4.24k|bool maybe_BER(DataSource& source) {
  232|  4.24k|   uint8_t first_u8 = 0;
  233|  4.24k|   if(source.peek_byte(first_u8) == 0) {
  ------------------
  |  Branch (233:7): [True: 1, False: 4.24k]
  ------------------
  234|      1|      BOTAN_ASSERT_EQUAL(source.read_byte(first_u8), 0, "Expected EOF");
  ------------------
  |  |   97|      1|   do {                                                                                                \
  |  |   98|      1|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                                    \
  |  |   99|      1|      if((expr1) != (expr2)) {                                                                         \
  |  |  ------------------
  |  |  |  Branch (99:10): [True: 0, False: 1]
  |  |  ------------------
  |  |  100|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                                           \
  |  |  101|      0|         Botan::assertion_failure(#expr1 " == " #expr2, assertion_made, __func__, __FILE__, __LINE__); \
  |  |  102|      0|      }                                                                                                \
  |  |  103|      1|   } while(0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded, False: 1]
  |  |  ------------------
  ------------------
  235|      1|      throw Stream_IO_Error("ASN1::maybe_BER: Source was empty");
  236|      1|   }
  237|       |
  238|  4.24k|   const auto cons_seq = static_cast<uint8_t>(ASN1_Class::Constructed) | static_cast<uint8_t>(ASN1_Type::Sequence);
  239|  4.24k|   return first_u8 == cons_seq;
  240|  4.24k|}

_ZN5Botan3OID11from_stringENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   80|  1.32k|OID OID::from_string(std::string_view str) {
   81|  1.32k|   if(str.empty()) {
  ------------------
  |  Branch (81:7): [True: 0, False: 1.32k]
  ------------------
   82|      0|      throw Invalid_Argument("OID::from_string argument must be non-empty");
   83|      0|   }
   84|       |
   85|  1.32k|   OID o = OID_Map::global_registry().str2oid(str);
   86|  1.32k|   if(o.has_value()) {
  ------------------
  |  Branch (86:7): [True: 1.32k, False: 0]
  ------------------
   87|  1.32k|      return o;
   88|  1.32k|   }
   89|       |
   90|       |   // Try to parse as a dotted decimal
   91|      0|   try {
   92|      0|      return OID(str);
   93|      0|   } catch(...) {}
   94|       |
   95|      0|   throw Lookup_Error(fmt("No OID associated with name '{}'", str));
   96|      0|}
_ZN5Botan3OIDC2ESt16initializer_listIjE:
   98|  18.5k|OID::OID(std::initializer_list<uint32_t> init) : m_id(init) {
   99|  18.5k|   oid_valid_check(m_id);
  100|  18.5k|}
_ZNK5Botan3OID9to_stringEv:
  123|  1.32k|std::string OID::to_string() const {
  124|  1.32k|   std::ostringstream out;
  125|       |
  126|  10.0k|   for(size_t i = 0; i != m_id.size(); ++i) {
  ------------------
  |  Branch (126:22): [True: 8.75k, False: 1.32k]
  ------------------
  127|       |      // avoid locale issues with integer formatting
  128|  8.75k|      out << std::to_string(m_id[i]);
  129|  8.75k|      if(i != m_id.size() - 1) {
  ------------------
  |  Branch (129:10): [True: 7.43k, False: 1.32k]
  ------------------
  130|  7.43k|         out << ".";
  131|  7.43k|      }
  132|  8.75k|   }
  133|       |
  134|  1.32k|   return out.str();
  135|  1.32k|}
_ZNK5Botan3OID15registered_nameEv:
  149|  1.32k|std::optional<std::string> OID::registered_name() const {
  150|  1.32k|   return OID_Map::global_registry().oid2str(*this);
  151|  1.32k|}
_ZNK5Botan3OID7matchesESt16initializer_listIjE:
  157|    342|bool OID::matches(std::initializer_list<uint32_t> other) const {
  158|       |   // TODO: once all target compilers support it, use std::ranges::equal
  159|    342|   return std::equal(m_id.begin(), m_id.end(), other.begin(), other.end());
  160|    342|}
_ZNK5Botan3OID9hash_codeEv:
  162|  2.64k|uint64_t OID::hash_code() const {
  163|       |   // If this is changed also update gen_oids.py to match
  164|  2.64k|   uint64_t hash = 0x621F302327D9A49A;
  165|  17.5k|   for(auto id : m_id) {
  ------------------
  |  Branch (165:16): [True: 17.5k, False: 2.64k]
  ------------------
  166|  17.5k|      hash *= 193;
  167|  17.5k|      hash += id;
  168|  17.5k|   }
  169|  2.64k|   return hash;
  170|  2.64k|}
_ZN5BotanltERKNS_3OIDES2_:
  175|  1.88k|bool operator<(const OID& a, const OID& b) {
  176|  1.88k|   const std::vector<uint32_t>& oid1 = a.get_components();
  177|  1.88k|   const std::vector<uint32_t>& oid2 = b.get_components();
  178|       |
  179|  1.88k|   return std::lexicographical_compare(oid1.begin(), oid1.end(), oid2.begin(), oid2.end());
  180|  1.88k|}
_ZNK5Botan3OID11encode_intoERNS_11DER_EncoderE:
  185|  2.26k|void OID::encode_into(DER_Encoder& der) const {
  186|  2.26k|   if(m_id.size() < 2) {
  ------------------
  |  Branch (186:7): [True: 0, False: 2.26k]
  ------------------
  187|      0|      throw Invalid_Argument("OID::encode_into: OID is invalid");
  188|      0|   }
  189|       |
  190|  2.26k|   auto append = [](std::vector<uint8_t>& encoding, uint32_t z) {
  191|  2.26k|      if(z <= 0x7F) {
  192|  2.26k|         encoding.push_back(static_cast<uint8_t>(z));
  193|  2.26k|      } else {
  194|  2.26k|         const size_t z7 = (high_bit(z) + 7 - 1) / 7;
  195|       |
  196|  2.26k|         for(size_t j = 0; j != z7; ++j) {
  197|  2.26k|            uint8_t zp = static_cast<uint8_t>(z >> (7 * (z7 - j - 1)) & 0x7F);
  198|       |
  199|  2.26k|            if(j != z7 - 1) {
  200|  2.26k|               zp |= 0x80;
  201|  2.26k|            }
  202|       |
  203|  2.26k|            encoding.push_back(zp);
  204|  2.26k|         }
  205|  2.26k|      }
  206|  2.26k|   };
  207|       |
  208|  2.26k|   std::vector<uint8_t> encoding;
  209|       |
  210|       |   // We know 40 * root can't overflow because root is between 0 and 2
  211|  2.26k|   auto first = checked_add(40 * m_id[0], m_id[1]);
  212|  2.26k|   BOTAN_ASSERT_NOMSG(first.has_value());
  ------------------
  |  |   84|  2.26k|   do {                                                                     \
  |  |   85|  2.26k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  2.26k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 2.26k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  2.26k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 2.26k]
  |  |  ------------------
  ------------------
  213|       |
  214|  2.26k|   append(encoding, *first);
  215|       |
  216|  5.83k|   for(size_t i = 2; i != m_id.size(); ++i) {
  ------------------
  |  Branch (216:22): [True: 3.57k, False: 2.26k]
  ------------------
  217|  3.57k|      append(encoding, m_id[i]);
  218|  3.57k|   }
  219|  2.26k|   der.add_object(ASN1_Type::ObjectId, ASN1_Class::Universal, encoding);
  220|  2.26k|}
_ZN5Botan3OID11decode_fromERNS_11BER_DecoderE:
  225|  7.92k|void OID::decode_from(BER_Decoder& decoder) {
  226|  7.92k|   const BER_Object obj = decoder.get_next_object();
  227|  7.92k|   if(obj.tagging() != (ASN1_Class::Universal | ASN1_Type::ObjectId)) {
  ------------------
  |  Branch (227:7): [True: 54, False: 7.87k]
  ------------------
  228|     54|      throw BER_Bad_Tag("Error decoding OID, unknown tag", obj.tagging());
  229|     54|   }
  230|       |
  231|  7.87k|   if(obj.length() == 0) {
  ------------------
  |  Branch (231:7): [True: 1, False: 7.87k]
  ------------------
  232|      1|      throw BER_Decoding_Error("OID encoding is too short");
  233|      1|   }
  234|       |
  235|  7.87k|   auto consume = [](BufferSlicer& data) -> uint32_t {
  236|  7.87k|      BOTAN_ASSERT_NOMSG(!data.empty());
  237|  7.87k|      uint32_t b = data.take_byte();
  238|       |
  239|  7.87k|      if(b > 0x7F) {
  240|  7.87k|         b &= 0x7F;
  241|       |
  242|       |         // Even BER requires that the OID have minimal length, ie that
  243|       |         // the first byte of a multibyte encoding cannot be zero
  244|       |         // See X.690 section 8.19.2
  245|  7.87k|         if(b == 0) {
  246|  7.87k|            throw Decoding_Error("Leading zero byte in multibyte OID encoding");
  247|  7.87k|         }
  248|       |
  249|  7.87k|         while(true) {
  250|  7.87k|            if(data.empty()) {
  251|  7.87k|               throw Decoding_Error("Truncated OID value");
  252|  7.87k|            }
  253|       |
  254|  7.87k|            const uint8_t next = data.take_byte();
  255|  7.87k|            const bool more = (next & 0x80) == 0x80;
  256|  7.87k|            const uint8_t value = next & 0x7F;
  257|       |
  258|  7.87k|            if((b >> (32 - 7)) != 0) {
  259|  7.87k|               throw Decoding_Error("OID component overflow");
  260|  7.87k|            }
  261|       |
  262|  7.87k|            b = (b << 7) | value;
  263|       |
  264|  7.87k|            if(!more) {
  265|  7.87k|               break;
  266|  7.87k|            }
  267|  7.87k|         }
  268|  7.87k|      }
  269|       |
  270|  7.87k|      return b;
  271|  7.87k|   };
  272|       |
  273|  7.87k|   BufferSlicer data(obj.data());
  274|  7.87k|   std::vector<uint32_t> parts;
  275|       |
  276|       |   // Each byte of the DER encoding can result in at most one additional arc,
  277|       |   // except the first byte which always encodes two.
  278|  7.87k|   parts.reserve(obj.length() + 1);
  279|       |
  280|  35.7k|   while(!data.empty()) {
  ------------------
  |  Branch (280:10): [True: 27.8k, False: 7.87k]
  ------------------
  281|  27.8k|      const uint32_t comp = consume(data);
  282|       |
  283|  27.8k|      if(parts.empty()) {
  ------------------
  |  Branch (283:10): [True: 7.85k, False: 20.0k]
  ------------------
  284|       |         // divide into root and second arc
  285|       |
  286|  7.85k|         const uint32_t root_arc = [](uint32_t b0) -> uint32_t {
  287|  7.85k|            if(b0 < 40) {
  288|  7.85k|               return 0;
  289|  7.85k|            } else if(b0 < 80) {
  290|  7.85k|               return 1;
  291|  7.85k|            } else {
  292|  7.85k|               return 2;
  293|  7.85k|            }
  294|  7.85k|         }(comp);
  295|       |
  296|  7.85k|         parts.push_back(root_arc);
  297|  7.85k|         BOTAN_ASSERT_NOMSG(comp >= 40 * root_arc);
  ------------------
  |  |   84|  7.85k|   do {                                                                     \
  |  |   85|  7.85k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  7.85k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 7.85k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  7.85k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 7.85k]
  |  |  ------------------
  ------------------
  298|  7.85k|         parts.push_back(comp - 40 * root_arc);
  299|  20.0k|      } else {
  300|  20.0k|         parts.push_back(comp);
  301|  20.0k|      }
  302|  27.8k|   }
  303|       |
  304|  7.87k|   m_id = std::move(parts);
  305|  7.87k|}
asn1_oid.cpp:_ZN5Botan12_GLOBAL__N_115oid_valid_checkENSt3__14spanIKjLm18446744073709551615EEE:
   26|  18.5k|void oid_valid_check(std::span<const uint32_t> oid) {
   27|  18.5k|   BOTAN_ARG_CHECK(oid.size() >= 2, "OID too short to be valid");
  ------------------
  |  |   35|  18.5k|   do {                                                          \
  |  |   36|  18.5k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  18.5k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 18.5k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  18.5k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 18.5k]
  |  |  ------------------
  ------------------
   28|  18.5k|   BOTAN_ARG_CHECK(oid[0] <= 2, "OID root out of range");
  ------------------
  |  |   35|  18.5k|   do {                                                          \
  |  |   36|  18.5k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  18.5k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 18.5k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  18.5k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 18.5k]
  |  |  ------------------
  ------------------
   29|  18.5k|   BOTAN_ARG_CHECK(oid[1] <= 39 || oid[0] == 2, "OID second arc too large");
  ------------------
  |  |   35|  18.5k|   do {                                                          \
  |  |   36|  18.5k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  18.5k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:12): [True: 18.5k, False: 0]
  |  |  |  Branch (37:12): [True: 0, False: 0]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  18.5k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 18.5k]
  |  |  ------------------
  ------------------
   30|       |   // This last is a limitation of using 32 bit integers when decoding
   31|       |   // not a limitation of ASN.1 object identifiers in general
   32|  18.5k|   BOTAN_ARG_CHECK(oid[1] <= 0xFFFFFFAF, "OID second arc too large");
  ------------------
  |  |   35|  18.5k|   do {                                                          \
  |  |   36|  18.5k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  18.5k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 18.5k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  18.5k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 18.5k]
  |  |  ------------------
  ------------------
   33|  18.5k|}
asn1_oid.cpp:_ZZNK5Botan3OID11encode_intoERNS_11DER_EncoderEENK3$_0clERNSt3__16vectorIhNS4_9allocatorIhEEEEj:
  190|  5.83k|   auto append = [](std::vector<uint8_t>& encoding, uint32_t z) {
  191|  5.83k|      if(z <= 0x7F) {
  ------------------
  |  Branch (191:10): [True: 2.50k, False: 3.33k]
  ------------------
  192|  2.50k|         encoding.push_back(static_cast<uint8_t>(z));
  193|  3.33k|      } else {
  194|  3.33k|         const size_t z7 = (high_bit(z) + 7 - 1) / 7;
  195|       |
  196|  11.8k|         for(size_t j = 0; j != z7; ++j) {
  ------------------
  |  Branch (196:28): [True: 8.48k, False: 3.33k]
  ------------------
  197|  8.48k|            uint8_t zp = static_cast<uint8_t>(z >> (7 * (z7 - j - 1)) & 0x7F);
  198|       |
  199|  8.48k|            if(j != z7 - 1) {
  ------------------
  |  Branch (199:16): [True: 5.15k, False: 3.33k]
  ------------------
  200|  5.15k|               zp |= 0x80;
  201|  5.15k|            }
  202|       |
  203|  8.48k|            encoding.push_back(zp);
  204|  8.48k|         }
  205|  3.33k|      }
  206|  5.83k|   };
asn1_oid.cpp:_ZZN5Botan3OID11decode_fromERNS_11BER_DecoderEENK3$_0clERNS_12BufferSlicerE:
  235|  27.8k|   auto consume = [](BufferSlicer& data) -> uint32_t {
  236|  27.8k|      BOTAN_ASSERT_NOMSG(!data.empty());
  ------------------
  |  |   84|  27.8k|   do {                                                                     \
  |  |   85|  27.8k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  27.8k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 27.8k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  27.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 27.8k]
  |  |  ------------------
  ------------------
  237|  27.8k|      uint32_t b = data.take_byte();
  238|       |
  239|  27.8k|      if(b > 0x7F) {
  ------------------
  |  Branch (239:10): [True: 10.5k, False: 17.3k]
  ------------------
  240|  10.5k|         b &= 0x7F;
  241|       |
  242|       |         // Even BER requires that the OID have minimal length, ie that
  243|       |         // the first byte of a multibyte encoding cannot be zero
  244|       |         // See X.690 section 8.19.2
  245|  10.5k|         if(b == 0) {
  ------------------
  |  Branch (245:13): [True: 2, False: 10.5k]
  ------------------
  246|      2|            throw Decoding_Error("Leading zero byte in multibyte OID encoding");
  247|      2|         }
  248|       |
  249|  15.6k|         while(true) {
  ------------------
  |  Branch (249:16): [True: 15.6k, Folded]
  ------------------
  250|  15.6k|            if(data.empty()) {
  ------------------
  |  Branch (250:16): [True: 11, False: 15.5k]
  ------------------
  251|     11|               throw Decoding_Error("Truncated OID value");
  252|     11|            }
  253|       |
  254|  15.5k|            const uint8_t next = data.take_byte();
  255|  15.5k|            const bool more = (next & 0x80) == 0x80;
  256|  15.5k|            const uint8_t value = next & 0x7F;
  257|       |
  258|  15.5k|            if((b >> (32 - 7)) != 0) {
  ------------------
  |  Branch (258:16): [True: 15, False: 15.5k]
  ------------------
  259|     15|               throw Decoding_Error("OID component overflow");
  260|     15|            }
  261|       |
  262|  15.5k|            b = (b << 7) | value;
  263|       |
  264|  15.5k|            if(!more) {
  ------------------
  |  Branch (264:16): [True: 10.5k, False: 5.06k]
  ------------------
  265|  10.5k|               break;
  266|  10.5k|            }
  267|  15.5k|         }
  268|  10.5k|      }
  269|       |
  270|  27.8k|      return b;
  271|  27.8k|   };
asn1_oid.cpp:_ZZN5Botan3OID11decode_fromERNS_11BER_DecoderEENK3$_1clEj:
  286|  7.85k|         const uint32_t root_arc = [](uint32_t b0) -> uint32_t {
  287|  7.85k|            if(b0 < 40) {
  ------------------
  |  Branch (287:16): [True: 2.41k, False: 5.44k]
  ------------------
  288|  2.41k|               return 0;
  289|  5.44k|            } else if(b0 < 80) {
  ------------------
  |  Branch (289:23): [True: 730, False: 4.71k]
  ------------------
  290|    730|               return 1;
  291|  4.71k|            } else {
  292|  4.71k|               return 2;
  293|  4.71k|            }
  294|  7.85k|         }(comp);

_ZN5Botan11ASN1_StringC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEENS_9ASN1_TypeE:
  135|  1.20k|ASN1_String::ASN1_String(std::string_view str, ASN1_Type t) : m_utf8_str(str), m_tag(t) {
  136|  1.20k|   if(!is_utf8_subset_string_type(m_tag)) {
  ------------------
  |  Branch (136:7): [True: 0, False: 1.20k]
  ------------------
  137|      0|      throw Invalid_Argument("ASN1_String only supports encoding to UTF-8 or a UTF-8 subset");
  138|      0|   }
  139|       |
  140|  1.20k|   if(!is_valid_asn1_string_content(m_utf8_str, m_tag)) {
  ------------------
  |  Branch (140:7): [True: 0, False: 1.20k]
  ------------------
  141|      0|      throw Invalid_Argument(fmt("ASN1_String: Invalid {} encoding", asn1_tag_to_string(m_tag)));
  142|      0|   }
  143|  1.20k|}
_ZN5Botan11ASN1_StringC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  145|  1.20k|ASN1_String::ASN1_String(std::string_view str) : ASN1_String(str, choose_encoding(str)) {}
_ZN5Botan11ASN1_String11decode_fromERNS_11BER_DecoderE:
  162|  1.17k|void ASN1_String::decode_from(BER_Decoder& source) {
  163|  1.17k|   const BER_Object obj = source.get_next_object();
  164|       |
  165|  1.17k|   if(obj.get_class() != ASN1_Class::Universal || !is_asn1_string_type(obj.type())) {
  ------------------
  |  Branch (165:7): [True: 11, False: 1.16k]
  |  Branch (165:51): [True: 59, False: 1.10k]
  ------------------
  166|     65|      auto typ = static_cast<uint32_t>(obj.type());
  167|     65|      auto cls = static_cast<uint32_t>(obj.get_class());
  168|     65|      throw Decoding_Error(fmt("ASN1_String: Unknown string type {}/{}", typ, cls));
  169|     65|   }
  170|       |
  171|  1.10k|   m_tag = obj.type();
  172|  1.10k|   m_data.assign(obj.bits(), obj.bits() + obj.length());
  173|       |
  174|  1.10k|   if(m_tag == ASN1_Type::BmpString) {
  ------------------
  |  Branch (174:7): [True: 125, False: 982]
  ------------------
  175|    125|      m_utf8_str = ucs2_to_utf8(m_data);
  176|    982|   } else if(m_tag == ASN1_Type::UniversalString) {
  ------------------
  |  Branch (176:14): [True: 66, False: 916]
  ------------------
  177|     66|      m_utf8_str = ucs4_to_utf8(m_data);
  178|    916|   } else if(m_tag == ASN1_Type::TeletexString) {
  ------------------
  |  Branch (178:14): [True: 231, False: 685]
  ------------------
  179|       |      /*
  180|       |      TeletexString is nominally ITU T.61 not ISO-8859-1 but it seems
  181|       |      the majority of implementations actually used that charset here.
  182|       |      */
  183|    231|      m_utf8_str = latin1_to_utf8(m_data);
  184|    685|   } else {
  185|       |      // All other supported string types are UTF-8 or some subset thereof
  186|    685|      m_utf8_str = ASN1::to_string(obj);
  187|       |
  188|    685|      if(!is_valid_asn1_string_content(m_utf8_str, m_tag)) {
  ------------------
  |  Branch (188:10): [True: 66, False: 619]
  ------------------
  189|     66|         throw Decoding_Error(fmt("ASN1_String: Invalid {} encoding", asn1_tag_to_string(m_tag)));
  190|     66|      }
  191|    685|   }
  192|  1.10k|}
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_119is_asn1_string_typeENS_9ASN1_TypeE:
   99|  1.16k|bool is_asn1_string_type(ASN1_Type tag) {
  100|  1.16k|   return (is_utf8_subset_string_type(tag) || tag == ASN1_Type::TeletexString || tag == ASN1_Type::BmpString ||
  ------------------
  |  Branch (100:12): [True: 680, False: 481]
  |  Branch (100:47): [True: 231, False: 250]
  |  Branch (100:82): [True: 125, False: 125]
  ------------------
  101|    125|           tag == ASN1_Type::UniversalString);
  ------------------
  |  Branch (101:12): [True: 66, False: 59]
  ------------------
  102|  1.16k|}
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_126is_utf8_subset_string_typeENS_9ASN1_TypeE:
   94|  4.25k|bool is_utf8_subset_string_type(ASN1_Type tag) {
   95|  4.25k|   return (tag == ASN1_Type::NumericString || tag == ASN1_Type::PrintableString || tag == ASN1_Type::VisibleString ||
  ------------------
  |  Branch (95:12): [True: 118, False: 4.13k]
  |  Branch (95:47): [True: 2.61k, False: 1.52k]
  |  Branch (95:84): [True: 146, False: 1.37k]
  ------------------
   96|  1.37k|           tag == ASN1_Type::Ia5String || tag == ASN1_Type::Utf8String);
  ------------------
  |  Branch (96:12): [True: 416, False: 963]
  |  Branch (96:43): [True: 482, False: 481]
  ------------------
   97|  4.25k|}
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_128is_valid_asn1_string_contentERKNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS_9ASN1_TypeE:
  104|  1.88k|bool is_valid_asn1_string_content(const std::string& str, ASN1_Type tag) {
  105|  1.88k|   BOTAN_ASSERT_NOMSG(is_utf8_subset_string_type(tag));
  ------------------
  |  |   84|  1.88k|   do {                                                                     \
  |  |   85|  1.88k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  1.88k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 1.88k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  1.88k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 1.88k]
  |  |  ------------------
  ------------------
  106|       |
  107|  1.88k|   switch(tag) {
  108|    241|      case ASN1_Type::Utf8String:
  ------------------
  |  Branch (108:7): [True: 241, False: 1.64k]
  ------------------
  109|    241|         return is_valid_utf8(str);
  110|     59|      case ASN1_Type::NumericString:
  ------------------
  |  Branch (110:7): [True: 59, False: 1.82k]
  ------------------
  111|  1.36k|      case ASN1_Type::PrintableString:
  ------------------
  |  Branch (111:7): [True: 1.30k, False: 581]
  ------------------
  112|  1.57k|      case ASN1_Type::Ia5String:
  ------------------
  |  Branch (112:7): [True: 208, False: 1.67k]
  ------------------
  113|  1.64k|      case ASN1_Type::VisibleString:
  ------------------
  |  Branch (113:7): [True: 73, False: 1.81k]
  ------------------
  114|  1.64k|         return g_char_validator.valid_encoding(str, tag);
  115|      0|      default:
  ------------------
  |  Branch (115:7): [True: 0, False: 1.88k]
  ------------------
  116|      0|         return false;
  117|  1.88k|   }
  118|  1.88k|}
asn1_str.cpp:_ZNK5Botan12_GLOBAL__N_131ASN1_String_Codepoint_Validator14valid_encodingENSt3__117basic_string_viewIcNS2_11char_traitsIcEEEENS_9ASN1_TypeE:
   25|  2.85k|      constexpr bool valid_encoding(std::string_view str, ASN1_Type tag) const {
   26|  2.85k|         const uint8_t mask = mask_for(tag);
   27|  2.85k|         for(const char c : str) {
  ------------------
  |  Branch (27:27): [True: 553, False: 2.84k]
  ------------------
   28|    553|            const uint8_t codepoint = static_cast<uint8_t>(c);
   29|    553|            const bool is_valid = (m_table[codepoint] & mask) != 0;
   30|       |
   31|    553|            if(!is_valid) {
  ------------------
  |  Branch (31:16): [True: 8, False: 545]
  ------------------
   32|      8|               return false;
   33|      8|            }
   34|    553|         }
   35|       |
   36|  2.84k|         return true;
   37|  2.85k|      }
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_131ASN1_String_Codepoint_Validator8mask_forENS_9ASN1_TypeE:
   45|  2.85k|      static constexpr uint8_t mask_for(ASN1_Type tag) {
   46|  2.85k|         switch(tag) {
   47|     59|            case ASN1_Type::NumericString:
  ------------------
  |  Branch (47:13): [True: 59, False: 2.79k]
  ------------------
   48|     59|               return Numeric_String;
   49|  2.51k|            case ASN1_Type::PrintableString:
  ------------------
  |  Branch (49:13): [True: 2.51k, False: 340]
  ------------------
   50|  2.51k|               return Printable_String;
   51|    208|            case ASN1_Type::Ia5String:
  ------------------
  |  Branch (51:13): [True: 208, False: 2.64k]
  ------------------
   52|    208|               return IA5_String;
   53|     73|            case ASN1_Type::VisibleString:
  ------------------
  |  Branch (53:13): [True: 73, False: 2.78k]
  ------------------
   54|     73|               return Visible_String;
   55|      0|            default:
  ------------------
  |  Branch (55:13): [True: 0, False: 2.85k]
  ------------------
   56|      0|               return 0;
   57|  2.85k|         }
   58|  2.85k|      }
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_115choose_encodingENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  120|  1.20k|ASN1_Type choose_encoding(std::string_view str) {
  121|  1.20k|   if(g_char_validator.valid_encoding(str, ASN1_Type::PrintableString)) {
  ------------------
  |  Branch (121:7): [True: 1.20k, False: 0]
  ------------------
  122|  1.20k|      return ASN1_Type::PrintableString;
  123|  1.20k|   } else {
  124|      0|      return ASN1_Type::Utf8String;
  125|      0|   }
  126|  1.20k|}

_ZN5Botan9ASN1_TimeC2EthhhhhNS_9ASN1_TypeE:
   43|  2.79k|      m_year(year), m_month(month), m_day(day), m_hour(hour), m_minute(minute), m_second(second), m_tag(tag) {
   44|  2.79k|   if(tag != ASN1_Type::UtcTime && tag != ASN1_Type::GeneralizedTime) {
  ------------------
  |  Branch (44:7): [True: 2.77k, False: 20]
  |  Branch (44:36): [True: 0, False: 2.77k]
  ------------------
   45|      0|      throw Invalid_Argument("ASN1_Time tag must be UtcTime or GeneralizedTime");
   46|      0|   }
   47|       |
   48|       |   /*
   49|       |   * RFC 5280 Section 4.1.2.5:
   50|       |   *    To indicate that a certificate has no well-defined expiration date,
   51|       |   *    the notAfter SHOULD be assigned the GeneralizedTime value of
   52|       |   *    99991231235959Z.
   53|       |   */
   54|  2.79k|   const uint16_t min_year = 1950;
   55|  2.79k|   const uint16_t max_year = (tag == ASN1_Type::UtcTime) ? 2049 : 9999;
  ------------------
  |  Branch (55:30): [True: 20, False: 2.77k]
  ------------------
   56|       |
   57|  2.79k|   if(m_year < min_year || m_year > max_year) {
  ------------------
  |  Branch (57:7): [True: 8, False: 2.78k]
  |  Branch (57:28): [True: 0, False: 2.78k]
  ------------------
   58|      8|      throw Invalid_Argument(fmt("ASN1_Time year {} is out of range ({} to {})", m_year, min_year, max_year));
   59|      8|   }
   60|       |
   61|  2.78k|   if(m_month < 1 || m_month > 12) {
  ------------------
  |  Branch (61:7): [True: 1, False: 2.78k]
  |  Branch (61:22): [True: 3, False: 2.78k]
  ------------------
   62|      4|      throw Invalid_Argument(fmt("ASN1_Time month {} is out of range", static_cast<uint32_t>(m_month)));
   63|      4|   }
   64|       |
   65|  2.78k|   constexpr uint8_t days_in_month[12] = {31, 28, 31, 30, 31, 30, 31, 31, 30, 31, 30, 31};
   66|       |
   67|  2.78k|   const bool is_leap_year = (m_year % 4 == 0) && (m_year % 100 != 0 || m_year % 400 == 0);
  ------------------
  |  Branch (67:30): [True: 1.19k, False: 1.58k]
  |  Branch (67:52): [True: 62, False: 1.13k]
  |  Branch (67:73): [True: 18, False: 1.11k]
  ------------------
   68|  2.78k|   const uint8_t max_day = (m_month == 2 && is_leap_year) ? 29 : days_in_month[m_month - 1];
  ------------------
  |  Branch (68:29): [True: 27, False: 2.75k]
  |  Branch (68:45): [True: 12, False: 15]
  ------------------
   69|       |
   70|  2.78k|   if(m_day < 1 || m_day > max_day) {
  ------------------
  |  Branch (70:7): [True: 2, False: 2.77k]
  |  Branch (70:20): [True: 4, False: 2.77k]
  ------------------
   71|      6|      throw Invalid_Argument(fmt("ASN1_Time day {} is out of range for month {}",
   72|      6|                                 static_cast<uint32_t>(m_day),
   73|      6|                                 static_cast<uint32_t>(m_month)));
   74|      6|   }
   75|       |
   76|  2.77k|   if(m_hour > 23) {
  ------------------
  |  Branch (76:7): [True: 3, False: 2.77k]
  ------------------
   77|      3|      throw Invalid_Argument(fmt("ASN1_Time hour {} is out of range", static_cast<uint32_t>(m_hour)));
   78|      3|   }
   79|       |
   80|  2.77k|   if(m_minute > 59) {
  ------------------
  |  Branch (80:7): [True: 2, False: 2.76k]
  ------------------
   81|      2|      throw Invalid_Argument(fmt("ASN1_Time minute {} is out of range", static_cast<uint32_t>(m_minute)));
   82|      2|   }
   83|       |
   84|       |   /*
   85|       |   * RFC 5280 is silent on the issue of leap seconds in certificate fields, but both
   86|       |   * OpenSSL and Go reject which suggests they are rarely if ever used in practice.
   87|       |   */
   88|  2.76k|   if(m_second > 59) {
  ------------------
  |  Branch (88:7): [True: 1, False: 2.76k]
  ------------------
   89|      1|      throw Invalid_Argument(fmt("ASN1_Time second {} is out of range", static_cast<uint32_t>(m_second)));
   90|      1|   }
   91|  2.76k|}
_ZN5Botan9ASN1_Time11from_stringENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEENS_9ASN1_TypeE:
  109|  2.81k|ASN1_Time ASN1_Time::from_string(std::string_view t_spec, ASN1_Type tag) {
  110|  2.81k|   BOTAN_ARG_CHECK(tag == ASN1_Type::UtcTime || tag == ASN1_Type::GeneralizedTime, "Invalid tag for ASN1_Time");
  ------------------
  |  |   35|  2.81k|   do {                                                          \
  |  |   36|  2.81k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  5.60k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:12): [True: 34, False: 2.78k]
  |  |  |  Branch (37:12): [True: 2.78k, False: 0]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  2.81k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 2.81k]
  |  |  ------------------
  ------------------
  111|       |
  112|  2.81k|   if(tag == ASN1_Type::GeneralizedTime) {
  ------------------
  |  Branch (112:7): [True: 2.78k, False: 34]
  ------------------
  113|  2.78k|      BOTAN_ARG_CHECK(t_spec.size() == 15, "Invalid GeneralizedTime input string");
  ------------------
  |  |   35|  2.78k|   do {                                                          \
  |  |   36|  2.78k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  2.78k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 4, False: 2.78k]
  |  |  ------------------
  |  |   38|      4|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      4|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      4|      }                                                          \
  |  |   41|  2.78k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 2.78k]
  |  |  ------------------
  ------------------
  114|  2.78k|   } else {
  115|     34|      BOTAN_ARG_CHECK(t_spec.size() == 13, "Invalid UTCTime input string");
  ------------------
  |  |   35|     34|   do {                                                          \
  |  |   36|     34|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|     34|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 6, False: 28]
  |  |  ------------------
  |  |   38|      6|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      6|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      6|      }                                                          \
  |  |   41|     34|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 34]
  |  |  ------------------
  ------------------
  116|     34|   }
  117|       |
  118|  2.81k|   BOTAN_ARG_CHECK(t_spec.back() == 'Z', "Botan does not support ASN1 times with timezones other than Z");
  ------------------
  |  |   35|  2.81k|   do {                                                          \
  |  |   36|  2.81k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  2.81k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 6, False: 2.81k]
  |  |  ------------------
  |  |   38|      6|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      6|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      6|      }                                                          \
  |  |   41|  2.81k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 2.81k]
  |  |  ------------------
  ------------------
  119|       |
  120|  2.81k|   const size_t field_len = 2;
  121|  2.81k|   const size_t year_len = (tag == ASN1_Type::UtcTime) ? 2 : 4;
  ------------------
  |  Branch (121:28): [True: 26, False: 2.79k]
  ------------------
  122|       |
  123|  2.81k|   const size_t year_start = 0;
  124|  2.81k|   const size_t month_start = year_start + year_len;
  125|  2.81k|   const size_t day_start = month_start + field_len;
  126|  2.81k|   const size_t hour_start = day_start + field_len;
  127|  2.81k|   const size_t min_start = hour_start + field_len;
  128|  2.81k|   const size_t sec_start = min_start + field_len;
  129|       |
  130|  2.81k|   uint32_t year = to_u32bit(t_spec.substr(year_start, year_len));
  131|  2.81k|   const uint32_t month = to_u32bit(t_spec.substr(month_start, field_len));
  132|  2.81k|   const uint32_t day = to_u32bit(t_spec.substr(day_start, field_len));
  133|  2.81k|   const uint32_t hour = to_u32bit(t_spec.substr(hour_start, field_len));
  134|  2.81k|   const uint32_t minute = to_u32bit(t_spec.substr(min_start, field_len));
  135|  2.81k|   const uint32_t second = to_u32bit(t_spec.substr(sec_start, field_len));
  136|       |
  137|  2.81k|   if(tag == ASN1_Type::UtcTime) {
  ------------------
  |  Branch (137:7): [True: 20, False: 2.79k]
  ------------------
  138|       |      // Interpret the two digit year by the 1950/2050 split (RFC 5280 Section 4.1.2.5.1)
  139|     20|      year += (year >= 50) ? 1900 : 2000;
  ------------------
  |  Branch (139:15): [True: 5, False: 15]
  ------------------
  140|     20|   }
  141|       |
  142|  2.81k|   return ASN1_Time(static_cast<uint16_t>(year),
  143|  2.81k|                    static_cast<uint8_t>(month),
  144|  2.81k|                    static_cast<uint8_t>(day),
  145|  2.81k|                    static_cast<uint8_t>(hour),
  146|  2.81k|                    static_cast<uint8_t>(minute),
  147|  2.81k|                    static_cast<uint8_t>(second),
  148|  2.81k|                    tag);
  149|  2.81k|}
_ZN5Botan9ASN1_Time11decode_fromERNS_11BER_DecoderE:
  168|  2.89k|void ASN1_Time::decode_from(BER_Decoder& source) {
  169|  2.89k|   const BER_Object ber_time = source.get_next_object();
  170|       |
  171|  2.89k|   if(ber_time.get_class() != ASN1_Class::Universal ||
  ------------------
  |  Branch (171:7): [True: 13, False: 2.88k]
  ------------------
  172|  2.88k|      (ber_time.type() != ASN1_Type::UtcTime && ber_time.type() != ASN1_Type::GeneralizedTime)) {
  ------------------
  |  Branch (172:8): [True: 2.84k, False: 34]
  |  Branch (172:49): [True: 64, False: 2.78k]
  ------------------
  173|     70|      throw Decoding_Error(fmt("ASN1_Time: Unexpected tag {}/{}",
  174|     70|                               static_cast<uint32_t>(ber_time.type()),
  175|     70|                               static_cast<uint32_t>(ber_time.get_class())));
  176|     70|   }
  177|       |
  178|  2.82k|   try {
  179|       |      // Assigning only after a successful parse means that a decoding error
  180|       |      // cannot leave this object in a partially written state
  181|  2.82k|      *this = ASN1_Time::from_string(ASN1::to_string(ber_time), ber_time.type());
  182|  2.82k|   } catch(Invalid_Argument& e) {
  183|     51|      throw Decoding_Error(fmt("Invalid ASN1_Time encoding: {}", e.what()));
  184|     51|   }
  185|  2.82k|}

_ZN5Botan11BER_DecoderD2Ev:
  456|  33.2k|BER_Decoder::~BER_Decoder() = default;
_ZNK5Botan11BER_Decoder10more_itemsEv:
  461|  6.12k|bool BER_Decoder::more_items() const {
  462|  6.12k|   if(m_source->end_of_data() && !m_pushed.is_set()) {
  ------------------
  |  Branch (462:7): [True: 4.10k, False: 2.02k]
  |  Branch (462:34): [True: 4.10k, False: 0]
  ------------------
  463|  4.10k|      return false;
  464|  4.10k|   }
  465|  2.02k|   return true;
  466|  6.12k|}
_ZN5Botan11BER_Decoder10verify_endEv:
  471|  3.45k|BER_Decoder& BER_Decoder::verify_end() {
  472|  3.45k|   return verify_end("BER_Decoder::verify_end called, but data remains");
  473|  3.45k|}
_ZN5Botan11BER_Decoder10verify_endENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  478|  4.81k|BER_Decoder& BER_Decoder::verify_end(std::string_view err) {
  479|  4.81k|   if(!m_source->end_of_data() || m_pushed.is_set()) {
  ------------------
  |  Branch (479:7): [True: 154, False: 4.66k]
  |  Branch (479:35): [True: 0, False: 4.66k]
  ------------------
  480|    154|      throw Decoding_Error(err);
  481|    154|   }
  482|  4.66k|   return (*this);
  483|  4.81k|}
_ZN5Botan11BER_Decoder10read_bytesENSt3__14spanIhLm18446744073709551615EEE:
  505|  18.6k|size_t BER_Decoder::read_bytes(std::span<uint8_t> out) {
  506|  18.6k|   BOTAN_ASSERT_NOMSG(m_source != nullptr);
  ------------------
  |  |   84|  18.6k|   do {                                                                     \
  |  |   85|  18.6k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  18.6k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 18.6k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  18.6k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 18.6k]
  |  |  ------------------
  ------------------
  507|  18.6k|   return m_source->read(out.data(), out.size());
  508|  18.6k|}
_ZN5Botan11BER_Decoder15get_next_objectEv:
  521|  47.8k|BER_Object BER_Decoder::get_next_object() {
  522|  47.8k|   BER_Object next;
  523|       |
  524|  47.8k|   if(m_pushed.is_set()) {
  ------------------
  |  Branch (524:7): [True: 2.08k, False: 45.7k]
  ------------------
  525|  2.08k|      std::swap(next, m_pushed);
  526|  2.08k|      return next;
  527|  2.08k|   }
  528|       |
  529|  45.7k|   for(;;) {
  530|  45.7k|      ASN1_Type type_tag = ASN1_Type::NoObject;
  531|  45.7k|      ASN1_Class class_tag = ASN1_Class::NoObject;
  532|  45.7k|      decode_tag(m_source, type_tag, class_tag);
  533|  45.7k|      next.set_tagging(type_tag, class_tag);
  534|  45.7k|      if(next.is_set() == false) {  // no more objects
  ------------------
  |  Branch (534:10): [True: 4.05k, False: 41.6k]
  ------------------
  535|  4.05k|         return next;
  536|  4.05k|      }
  537|       |
  538|  41.6k|      const size_t allow_indef = m_limits.allow_ber_encoding() ? m_limits.max_nested_indefinite_length() : 0;
  ------------------
  |  Branch (538:34): [True: 0, False: 41.6k]
  ------------------
  539|  41.6k|      const bool der_mode = m_limits.require_der_encoding();
  540|  41.6k|      const auto dl = decode_length(m_source, allow_indef, der_mode, is_constructed(class_tag));
  541|       |
  542|       |      // Per X.690 8.1.5 the only valid EOC encoding is the two-octet
  543|       |      // sequence 0x00 0x00. Reject any other length encoding on a tag of
  544|       |      // (Eoc, Universal) before we consume the "content" bytes.
  545|  41.6k|      if(type_tag == ASN1_Type::Eoc && class_tag == ASN1_Class::Universal &&
  ------------------
  |  Branch (545:10): [True: 168, False: 41.5k]
  |  Branch (545:40): [True: 141, False: 27]
  ------------------
  546|    141|         (dl.content_length() != 0 || dl.indefinite_length())) {
  ------------------
  |  Branch (546:11): [True: 71, False: 70]
  |  Branch (546:39): [True: 0, False: 70]
  ------------------
  547|     71|         throw BER_Decoding_Error("EOC marker with non-zero length");
  548|     71|      }
  549|       |
  550|  41.6k|      if(const auto max_size = m_limits.max_object_size(); max_size && dl.content_length() > *max_size) {
  ------------------
  |  Branch (550:60): [True: 41.3k, False: 233]
  |  Branch (550:72): [True: 36, False: 41.3k]
  ------------------
  551|     36|         throw BER_Decoding_Error("Encoded object exceeds maximum size");
  552|     36|      }
  553|       |
  554|  41.5k|      if(!m_source->check_available(dl.total_length())) {
  ------------------
  |  Branch (554:10): [True: 165, False: 41.4k]
  ------------------
  555|    165|         throw BER_Decoding_Error("Value truncated");
  556|    165|      }
  557|       |
  558|  41.4k|      uint8_t* out = next.mutable_bits(dl.content_length());
  559|  41.4k|      if(m_source->read(out, dl.content_length()) != dl.content_length()) {
  ------------------
  |  Branch (559:10): [True: 0, False: 41.4k]
  ------------------
  560|      0|         throw BER_Decoding_Error("Value truncated");
  561|      0|      }
  562|       |
  563|  41.4k|      if(dl.indefinite_length()) {
  ------------------
  |  Branch (563:10): [True: 0, False: 41.4k]
  ------------------
  564|       |         // After reading the data consume the 2-byte EOC
  565|      0|         uint8_t eoc[2] = {0xFF, 0xFF};
  566|      0|         if(m_source->read(eoc, 2) != 2 || eoc[0] != 0x00 || eoc[1] != 0x00) {
  ------------------
  |  Branch (566:13): [True: 0, False: 0]
  |  Branch (566:44): [True: 0, False: 0]
  |  Branch (566:62): [True: 0, False: 0]
  ------------------
  567|      0|            throw BER_Decoding_Error("Missing or malformed EOC marker");
  568|      0|         }
  569|      0|      }
  570|       |
  571|  41.4k|      if(next.tagging() == static_cast<uint32_t>(ASN1_Type::Eoc)) {
  ------------------
  |  Branch (571:10): [True: 70, False: 41.3k]
  ------------------
  572|     70|         if(m_limits.require_der_encoding()) {
  ------------------
  |  Branch (572:13): [True: 70, False: 0]
  ------------------
  573|     70|            throw BER_Decoding_Error("Detected EOC marker in DER structure");
  574|     70|         }
  575|       |         // An EOC marker is only valid as an indefinite-length terminator, which
  576|       |         // is consumed above when reading the indefinite-length object. A
  577|       |         // standalone EOC is rejected unless the caller opted to tolerate it.
  578|      0|         if(m_limits.allow_standalone_eoc()) {
  ------------------
  |  Branch (578:13): [True: 0, False: 0]
  ------------------
  579|      0|            continue;
  580|      0|         }
  581|      0|         throw BER_Decoding_Error("Encountered EOC marker outside of indefinite-length encoding");
  582|      0|      }
  583|       |
  584|  41.3k|      break;
  585|  41.4k|   }
  586|       |
  587|  41.3k|   return next;
  588|  45.7k|}
_ZN5Botan11BER_Decoder9push_backEONS_10BER_ObjectE:
  612|  4.77k|void BER_Decoder::push_back(BER_Object&& obj) {
  613|  4.77k|   if(m_pushed.is_set()) {
  ------------------
  |  Branch (613:7): [True: 0, False: 4.77k]
  ------------------
  614|      0|      throw Invalid_State("BER_Decoder: Only one push back is allowed");
  615|      0|   }
  616|  4.77k|   m_pushed = std::move(obj);
  617|  4.77k|}
_ZN5Botan11BER_Decoder10start_consENS_9ASN1_TypeENS_10ASN1_ClassE:
  619|  21.4k|BER_Decoder BER_Decoder::start_cons(ASN1_Type type_tag, ASN1_Class class_tag) {
  620|  21.4k|   BER_Object obj = get_next_object();
  621|  21.4k|   obj.assert_is_a(type_tag, class_tag | ASN1_Class::Constructed);
  622|       |
  623|       |   // In DER mode the elements of a universal SET must appear in sorted order
  624|  21.4k|   if(m_limits.require_der_encoding() && type_tag == ASN1_Type::Set && class_tag == ASN1_Class::Universal) {
  ------------------
  |  Branch (624:7): [True: 20.7k, False: 762]
  |  Branch (624:42): [True: 795, False: 19.9k]
  |  Branch (624:72): [True: 795, False: 0]
  ------------------
  625|    795|      verify_set_is_sorted(std::span<const uint8_t>{obj.bits(), obj.length()});
  626|    795|   }
  627|       |
  628|  21.4k|   BER_Decoder child(std::move(obj), this);
  629|  21.4k|   return child;
  630|  21.4k|}
_ZN5Botan11BER_Decoder8end_consEv:
  635|  18.9k|BER_Decoder& BER_Decoder::end_cons() {
  636|  18.9k|   if(m_parent == nullptr) {
  ------------------
  |  Branch (636:7): [True: 0, False: 18.9k]
  ------------------
  637|      0|      throw Invalid_State("BER_Decoder::end_cons called with null parent");
  638|      0|   }
  639|  18.9k|   if(!m_source->end_of_data() || m_pushed.is_set()) {
  ------------------
  |  Branch (639:7): [True: 13, False: 18.9k]
  |  Branch (639:35): [True: 0, False: 18.9k]
  ------------------
  640|     13|      throw Decoding_Error("BER_Decoder::end_cons called with data left");
  641|     13|   }
  642|  18.9k|   return (*m_parent);
  643|  18.9k|}
_ZN5Botan11BER_DecoderC2EONS_10BER_ObjectEPS0_:
  646|  20.4k|      m_limits(parent != nullptr ? parent->limits() : BER_Decoder::Limits::BER()), m_parent(parent) {
  ------------------
  |  Branch (646:16): [True: 20.4k, False: 0]
  ------------------
  647|  20.4k|   m_data_src = std::make_unique<DataSource_BERObject>(std::move(obj));
  648|  20.4k|   m_source = m_data_src.get();
  649|  20.4k|}
_ZN5Botan11BER_DecoderC2ERNS_10DataSourceENS0_6LimitsE:
  659|  4.04k|BER_Decoder::BER_Decoder(DataSource& src, Limits limits) : m_limits(limits), m_source(&src) {}
_ZN5Botan11BER_DecoderC2ENSt3__14spanIKhLm18446744073709551615EEENS0_6LimitsE:
  664|  8.66k|BER_Decoder::BER_Decoder(std::span<const uint8_t> buf, Limits limits) : m_limits(limits) {
  665|  8.66k|   m_data_src = std::make_unique<DataSource_Memory>(buf);
  666|  8.66k|   m_source = m_data_src.get();
  667|  8.66k|}
_ZN5Botan11BER_Decoder6decodeERNS_11ASN1_ObjectENS_9ASN1_TypeENS_10ASN1_ClassE:
  676|  25.2k|BER_Decoder& BER_Decoder::decode(ASN1_Object& obj, ASN1_Type type_tag, ASN1_Class class_tag) {
  677|       |   // TODO support this case properly
  678|  25.2k|   if(type_tag != ASN1_Type::NoObject || class_tag != ASN1_Class::NoObject) {
  ------------------
  |  Branch (678:7): [True: 0, False: 25.2k]
  |  Branch (678:42): [True: 0, False: 25.2k]
  ------------------
  679|      0|      throw Not_Implemented("BER_Decoder::decode(ASN1_Object) does not support implicit tagged decoding");
  680|      0|   }
  681|  25.2k|   obj.decode_from(*this);
  682|  25.2k|   return (*this);
  683|  25.2k|}
_ZN5Botan11BER_Decoder6decodeERmNS_9ASN1_TypeENS_10ASN1_ClassE:
  730|     13|BER_Decoder& BER_Decoder::decode(size_t& out, ASN1_Type type_tag, ASN1_Class class_tag) {
  731|     13|   BigInt integer;
  732|     13|   decode(integer, type_tag, class_tag);
  733|       |
  734|     13|   if(integer.signum() < 0) {
  ------------------
  |  Branch (734:7): [True: 3, False: 10]
  ------------------
  735|      3|      throw BER_Decoding_Error("Decoded small integer value was negative");
  736|      3|   }
  737|       |
  738|     10|   if(integer.bits() > 32) {
  ------------------
  |  Branch (738:7): [True: 1, False: 9]
  ------------------
  739|      1|      throw BER_Decoding_Error("Decoded integer value larger than expected");
  740|      1|   }
  741|       |
  742|      9|   out = 0;
  743|     41|   for(size_t i = 0; i != 4; ++i) {
  ------------------
  |  Branch (743:22): [True: 32, False: 9]
  ------------------
  744|     32|      out = (out << 8) | integer.byte_at(3 - i);
  745|     32|   }
  746|       |
  747|      9|   return (*this);
  748|     10|}
_ZN5Botan11BER_Decoder6decodeERNS_6BigIntENS_9ASN1_TypeENS_10ASN1_ClassE:
  780|  2.06k|BER_Decoder& BER_Decoder::decode(BigInt& out, ASN1_Type type_tag, ASN1_Class class_tag) {
  781|  2.06k|   const BER_Object obj = get_next_object();
  782|  2.06k|   obj.assert_is_a(type_tag, class_tag);
  783|       |
  784|       |   // An INTEGER must have at least one content octet (X.690 section 8.3.1)
  785|  2.06k|   if(obj.length() == 0) {
  ------------------
  |  Branch (785:7): [True: 1, False: 2.06k]
  ------------------
  786|      1|      throw BER_Decoding_Error("INTEGER encoding has no content octets");
  787|      1|   }
  788|       |
  789|       |   // DER requires minimal INTEGER encoding (X.690 section 8.3.2)
  790|  2.06k|   if(m_limits.require_der_encoding()) {
  ------------------
  |  Branch (790:7): [True: 1.98k, False: 75]
  ------------------
  791|  1.98k|      if(obj.length() > 1) {
  ------------------
  |  Branch (791:10): [True: 228, False: 1.75k]
  ------------------
  792|    228|         if(obj.bits()[0] == 0x00 && (obj.bits()[1] & 0x80) == 0) {
  ------------------
  |  Branch (792:13): [True: 77, False: 151]
  |  Branch (792:38): [True: 1, False: 76]
  ------------------
  793|      1|            throw BER_Decoding_Error("Detected non-minimal INTEGER encoding in DER structure");
  794|      1|         }
  795|    227|         if(obj.bits()[0] == 0xFF && (obj.bits()[1] & 0x80) != 0) {
  ------------------
  |  Branch (795:13): [True: 23, False: 204]
  |  Branch (795:38): [True: 8, False: 15]
  ------------------
  796|      8|            throw BER_Decoding_Error("Detected non-minimal INTEGER encoding in DER structure");
  797|      8|         }
  798|    227|      }
  799|  1.98k|   }
  800|       |
  801|  2.05k|   out = ASN1::integer_from_contents(obj.data());
  802|       |
  803|  2.05k|   return (*this);
  804|  2.06k|}
_ZN5Botan4ASN121integer_from_contentsENSt3__14spanIKhLm18446744073709551615EEE:
  806|  3.10k|BigInt ASN1::integer_from_contents(std::span<const uint8_t> contents) {
  807|  3.10k|   if(contents.empty()) {
  ------------------
  |  Branch (807:7): [True: 0, False: 3.10k]
  ------------------
  808|      0|      throw BER_Decoding_Error("INTEGER encoding has no content octets");
  809|      0|   }
  810|       |
  811|  3.10k|   BigInt out;
  812|       |
  813|  3.10k|   const bool negative = (contents[0] & 0x80) == 0x80;
  814|       |
  815|  3.10k|   if(negative) {
  ------------------
  |  Branch (815:7): [True: 2.43k, False: 664]
  ------------------
  816|  2.43k|      secure_vector<uint8_t> vec(contents.begin(), contents.end());
  817|  2.67k|      for(size_t i = vec.size(); i > 0; --i) {
  ------------------
  |  Branch (817:34): [True: 2.67k, False: 0]
  ------------------
  818|  2.67k|         const bool gt0 = (vec[i - 1] > 0);
  819|  2.67k|         vec[i - 1] -= 1;
  820|  2.67k|         if(gt0) {
  ------------------
  |  Branch (820:13): [True: 2.43k, False: 239]
  ------------------
  821|  2.43k|            break;
  822|  2.43k|         }
  823|  2.67k|      }
  824|  3.79k|      for(auto& byte : vec) {
  ------------------
  |  Branch (824:22): [True: 3.79k, False: 2.43k]
  ------------------
  825|  3.79k|         byte = ~byte;
  826|  3.79k|      }
  827|  2.43k|      out._assign_from_bytes(vec);
  828|  2.43k|      out.set_sign(BigInt::Negative);
  829|  2.43k|   } else {
  830|    664|      out._assign_from_bytes(contents);
  831|    664|   }
  832|       |
  833|  3.10k|   return out;
  834|  3.10k|}
_ZN5Botan11BER_Decoder6decodeERNSt3__16vectorIhNS1_9allocatorIhEEEENS_9ASN1_TypeES7_NS_10ASN1_ClassE:
 1038|     16|                                 ASN1_Class class_tag) {
 1039|     16|   if(real_type != ASN1_Type::OctetString && real_type != ASN1_Type::BitString) {
  ------------------
  |  Branch (1039:7): [True: 16, False: 0]
  |  Branch (1039:46): [True: 0, False: 16]
  ------------------
 1040|      0|      throw BER_Bad_Tag("Bad tag for {BIT,OCTET} STRING", static_cast<uint32_t>(real_type));
 1041|      0|   }
 1042|       |
 1043|     16|   asn1_decode_binary_string(buffer, get_next_object(), real_type, type_tag, class_tag, m_limits);
 1044|     16|   return (*this);
 1045|     16|}
_ZN5Botan11BER_Decoder16decode_bitstringERNS_14ASN1_BitStringENS_9ASN1_TypeENS_10ASN1_ClassE:
 1047|  4.77k|BER_Decoder& BER_Decoder::decode_bitstring(ASN1_BitString& out, ASN1_Type type_tag, ASN1_Class class_tag) {
 1048|  4.77k|   const BER_Object obj = get_next_object();
 1049|       |
 1050|  4.77k|   std::vector<uint8_t> bits;
 1051|  4.77k|   uint8_t unused_bits = 0;
 1052|       |
 1053|  4.77k|   if(is_constructed(obj.class_tag())) {
  ------------------
  |  Branch (1053:7): [True: 1, False: 4.77k]
  ------------------
 1054|      1|      obj.assert_is_a(type_tag, class_tag | ASN1_Class::Constructed);
 1055|      1|      if(m_limits.require_der_encoding()) {
  ------------------
  |  Branch (1055:10): [True: 1, False: 0]
  ------------------
 1056|      1|         throw BER_Decoding_Error("Detected constructed string encoding in DER structure");
 1057|      1|      }
 1058|      0|      bits.reserve(obj.length());  // upper possible bound on the output size
 1059|      0|      unused_bits = asn1_concat_constructed_bit_string(bits, obj, m_limits, 0);
 1060|  4.77k|   } else {
 1061|  4.77k|      unused_bits = asn1_bitstring_unused_bits(obj, type_tag, class_tag, m_limits.require_der_encoding());
 1062|  4.77k|      bits.assign(obj.bits() + 1, obj.bits() + obj.length());
 1063|  4.77k|   }
 1064|       |
 1065|  4.77k|   if(unused_bits > 0 && !bits.empty()) {
  ------------------
  |  Branch (1065:7): [True: 5, False: 4.76k]
  |  Branch (1065:26): [True: 5, False: 0]
  ------------------
 1066|      5|      bits.back() &= static_cast<uint8_t>(0xFF << unused_bits);
 1067|      5|   }
 1068|       |
 1069|  4.77k|   out = ASN1_BitString(std::move(bits), unused_bits);
 1070|  4.77k|   return (*this);
 1071|  4.77k|}
_ZN5Botan4ASN120is_single_der_objectENSt3__14spanIKhLm18446744073709551615EEENS_9ASN1_TypeENS_10ASN1_ClassE:
 1105|    391|bool is_single_der_object(std::span<const uint8_t> bytes, ASN1_Type expected_type, ASN1_Class expected_class) {
 1106|    391|   if(bytes.empty()) {
  ------------------
  |  Branch (1106:7): [True: 0, False: 391]
  ------------------
 1107|      0|      return false;
 1108|      0|   }
 1109|       |
 1110|    391|   try {
 1111|    391|      DataSource_Span src(bytes);
 1112|       |
 1113|    391|      ASN1_Type type_tag = ASN1_Type::NoObject;
 1114|    391|      ASN1_Class class_tag = ASN1_Class::NoObject;
 1115|    391|      const size_t tag_bytes = decode_tag(&src, type_tag, class_tag);
 1116|       |
 1117|    391|      if(type_tag != expected_type || class_tag != expected_class) {
  ------------------
  |  Branch (1117:10): [True: 307, False: 84]
  |  Branch (1117:39): [True: 6, False: 78]
  ------------------
 1118|    295|         return false;
 1119|    295|      }
 1120|       |
 1121|     96|      const auto dl = decode_length(&src, /*allow_indef=*/0, /*der_mode=*/true, is_constructed(expected_class));
 1122|       |
 1123|     96|      const size_t header_bytes = tag_bytes + dl.field_length();
 1124|     96|      if(header_bytes > bytes.size()) {
  ------------------
  |  Branch (1124:10): [True: 0, False: 96]
  ------------------
 1125|      0|         return false;
 1126|      0|      }
 1127|     96|      return dl.content_length() == bytes.size() - header_bytes;
 1128|     96|   } catch(Decoding_Error&) {
 1129|     19|      return false;
 1130|     19|   }
 1131|    391|}
_ZN5Botan4ASN122is_der_sequence_headerENSt3__14spanIKhLm18446744073709551615EEE:
 1133|    139|bool is_der_sequence_header(std::span<const uint8_t> bytes) {
 1134|    139|   return is_single_der_object(bytes, ASN1_Type::Sequence, ASN1_Class::Universal | ASN1_Class::Constructed);
 1135|    139|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_110decode_tagEPNS_10DataSourceERNS_9ASN1_TypeERNS_10ASN1_ClassE:
   29|  46.1k|size_t decode_tag(DataSource* ber, ASN1_Type& type_tag, ASN1_Class& class_tag) {
   30|  46.1k|   auto b = ber->read_byte();
   31|       |
   32|  46.1k|   if(!b) {
  ------------------
  |  Branch (32:7): [True: 4.05k, False: 42.0k]
  ------------------
   33|  4.05k|      type_tag = ASN1_Type::NoObject;
   34|  4.05k|      class_tag = ASN1_Class::NoObject;
   35|  4.05k|      return 0;
   36|  4.05k|   }
   37|       |
   38|  42.0k|   if((*b & 0x1F) != 0x1F) {
  ------------------
  |  Branch (38:7): [True: 41.5k, False: 582]
  ------------------
   39|  41.5k|      type_tag = ASN1_Type(*b & 0x1F);
   40|  41.5k|      class_tag = ASN1_Class(*b & 0xE0);
   41|       |      // The EOC marker is primitive; a constructed universal tag 0 has no
   42|       |      // valid meaning and would otherwise bypass the EOC handling, which
   43|       |      // matches on (Eoc, Universal) exactly
   44|  41.5k|      if(type_tag == ASN1_Type::Eoc && class_tag == ASN1_Class::Constructed) {
  ------------------
  |  Branch (44:10): [True: 229, False: 41.2k]
  |  Branch (44:40): [True: 11, False: 218]
  ------------------
   45|     11|         throw BER_Decoding_Error("EOC tag with constructed encoding");
   46|     11|      }
   47|  41.4k|      return 1;
   48|  41.5k|   }
   49|       |
   50|    582|   size_t tag_bytes = 1;
   51|    582|   class_tag = ASN1_Class(*b & 0xE0);
   52|       |
   53|    582|   uint32_t tag_buf = 0;
   54|  2.10k|   while(true) {
  ------------------
  |  Branch (54:10): [True: 2.10k, Folded]
  ------------------
   55|  2.10k|      b = ber->read_byte();
   56|  2.10k|      if(!b) {
  ------------------
  |  Branch (56:10): [True: 16, False: 2.08k]
  ------------------
   57|     16|         throw BER_Decoding_Error("Long-form tag truncated");
   58|     16|      }
   59|       |      // Reject if shifting in another 7 bits would overflow the uint32_t tag
   60|  2.08k|      if((tag_buf >> 25) != 0) {
  ------------------
  |  Branch (60:10): [True: 22, False: 2.06k]
  ------------------
   61|     22|         throw BER_Decoding_Error("Long-form tag overflowed 32 bits");
   62|     22|      }
   63|       |      // This is required even by BER (see X.690 section 8.1.2.4.2 sentence c).
   64|       |      // Bits 7-1 of the first subsequent octet must not be all zero; this rules
   65|       |      // out both 0x80 (continuation with no data) and 0x00 (a long-form encoding
   66|       |      // of tag value 0, which collides with the EOC marker).
   67|  2.06k|      if(tag_bytes == 1 && (*b & 0x7F) == 0) {
  ------------------
  |  Branch (67:10): [True: 578, False: 1.48k]
  |  Branch (67:28): [True: 12, False: 566]
  ------------------
   68|     12|         throw BER_Decoding_Error("Long form tag with leading zero");
   69|     12|      }
   70|  2.05k|      ++tag_bytes;
   71|  2.05k|      tag_buf = (tag_buf << 7) | (*b & 0x7F);
   72|  2.05k|      if((*b & 0x80) == 0) {
  ------------------
  |  Branch (72:10): [True: 532, False: 1.51k]
  ------------------
   73|    532|         break;
   74|    532|      }
   75|  2.05k|   }
   76|       |   // Per X.690 8.1.2.2, tag values 0-30 shall be encoded in the short form.
   77|       |   // Long-form encoding is reserved for tag values >= 31 (X.690 8.1.2.3).
   78|       |   // This is unconditional and applies to BER as well as DER.
   79|    532|   if(tag_buf <= 30) {
  ------------------
  |  Branch (79:7): [True: 9, False: 523]
  ------------------
   80|      9|      throw BER_Decoding_Error("Long-form tag encoding used for small tag value");
   81|      9|   }
   82|       |
   83|    523|   if(tag_buf == static_cast<uint32_t>(ASN1_Type::NoObject)) {
  ------------------
  |  Branch (83:7): [True: 4, False: 519]
  ------------------
   84|      4|      throw BER_Decoding_Error("Tag value collides with internal sentinel");
   85|      4|   }
   86|       |
   87|       |   // NOLINTNEXTLINE(clang-analyzer-optin.core.EnumCastOutOfRange)
   88|    519|   type_tag = ASN1_Type(tag_buf);
   89|    519|   return tag_bytes;
   90|    523|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_113decode_lengthEPNS_10DataSourceEmbb:
  135|  41.7k|BerDecodedLength decode_length(DataSource* ber, size_t allow_indef, bool der_mode, bool constructed) {
  136|  41.7k|   uint8_t b = 0;
  137|  41.7k|   if(ber->read_byte(b) == 0) {
  ------------------
  |  Branch (137:7): [True: 90, False: 41.6k]
  ------------------
  138|     90|      throw BER_Decoding_Error("Length field not found");
  139|     90|   }
  140|  41.6k|   if((b & 0x80) == 0) {
  ------------------
  |  Branch (140:7): [True: 41.2k, False: 333]
  ------------------
  141|  41.2k|      return BerDecodedLength(b, 1);
  142|  41.2k|   }
  143|       |
  144|    333|   const size_t num_length_bytes = (b & 0x7F);
  145|    333|   if(num_length_bytes > 4) {
  ------------------
  |  Branch (145:7): [True: 57, False: 276]
  ------------------
  146|     57|      throw BER_Decoding_Error("Length field is too large");
  147|     57|   }
  148|       |
  149|    276|   const size_t field_size = 1 + num_length_bytes;
  150|       |
  151|    276|   if(num_length_bytes == 0) {
  ------------------
  |  Branch (151:7): [True: 13, False: 263]
  ------------------
  152|     13|      if(der_mode) {
  ------------------
  |  Branch (152:10): [True: 13, False: 0]
  ------------------
  153|     13|         throw BER_Decoding_Error("Detected indefinite-length encoding in DER structure");
  154|     13|      } else if(!constructed) {
  ------------------
  |  Branch (154:17): [True: 0, False: 0]
  ------------------
  155|       |         // Indefinite length is only valid for constructed types (X.690 8.1.3.2)
  156|      0|         throw BER_Decoding_Error("Indefinite-length encoding used with non-constructed type");
  157|      0|      } else if(allow_indef == 0) {
  ------------------
  |  Branch (157:17): [True: 0, False: 0]
  ------------------
  158|      0|         throw BER_Decoding_Error("Nested EOC markers too deep, rejecting to avoid stack exhaustion");
  159|      0|      } else {
  160|       |         // find_eoc returns bytes up to and including the EOC marker.
  161|       |         // Return the content length; the caller consumes the EOC separately.
  162|      0|         const size_t eoc_len = find_eoc(ber, /*base_offset=*/0, allow_indef - 1);
  163|      0|         if(eoc_len < 2) {
  ------------------
  |  Branch (163:13): [True: 0, False: 0]
  ------------------
  164|      0|            throw BER_Decoding_Error("Invalid EOC encoding");
  165|      0|         }
  166|      0|         return BerDecodedLength::indefinite(eoc_len - 2, field_size);
  167|      0|      }
  168|     13|   }
  169|       |
  170|    263|   size_t length = 0;
  171|       |
  172|    916|   for(size_t i = 0; i != num_length_bytes; ++i) {
  ------------------
  |  Branch (172:22): [True: 661, False: 255]
  ------------------
  173|    661|      if(ber->read_byte(b) == 0) {
  ------------------
  |  Branch (173:10): [True: 8, False: 653]
  ------------------
  174|      8|         throw BER_Decoding_Error("Corrupted length field");
  175|      8|      }
  176|       |      // Can't overflow since we already checked that num_length_bytes <= 4
  177|    653|      length = (length << 8) | b;
  178|    653|   }
  179|       |
  180|       |   // DER requires shortest possible length encoding
  181|    255|   if(der_mode) {
  ------------------
  |  Branch (181:7): [True: 255, False: 0]
  ------------------
  182|    255|      if(length < 128) {
  ------------------
  |  Branch (182:10): [True: 7, False: 248]
  ------------------
  183|      7|         throw BER_Decoding_Error("Detected non-canonical length encoding in DER structure");
  184|      7|      }
  185|    248|      if(num_length_bytes > 1 && length < (size_t(1) << ((num_length_bytes - 1) * 8))) {
  ------------------
  |  Branch (185:10): [True: 186, False: 62]
  |  Branch (185:34): [True: 3, False: 183]
  ------------------
  186|      3|         throw BER_Decoding_Error("Detected non-canonical length encoding in DER structure");
  187|      3|      }
  188|    248|   }
  189|       |
  190|    245|   return BerDecodedLength(length, field_size);
  191|    255|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_116BerDecodedLengthC2Emm:
  108|  41.5k|            BerDecodedLength(content_length, field_length, false) {}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_116BerDecodedLengthC2Emmb:
  125|  41.5k|            m_content_length(content_length), m_field_length(field_length), m_indefinite(indefinite) {}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_18peek_tagEPNS_10DataSourceEmRNS_9ASN1_TypeERNS_10ASN1_ClassE:
  197|  1.92k|size_t peek_tag(DataSource* src, size_t offset, ASN1_Type& type_tag, ASN1_Class& class_tag) {
  198|  1.92k|   uint8_t b = 0;
  199|  1.92k|   if(src->peek(&b, 1, offset) == 0) {
  ------------------
  |  Branch (199:7): [True: 0, False: 1.92k]
  ------------------
  200|      0|      type_tag = ASN1_Type::NoObject;
  201|      0|      class_tag = ASN1_Class::NoObject;
  202|      0|      return 0;
  203|      0|   }
  204|       |
  205|  1.92k|   if((b & 0x1F) != 0x1F) {
  ------------------
  |  Branch (205:7): [True: 1.75k, False: 165]
  ------------------
  206|  1.75k|      type_tag = ASN1_Type(b & 0x1F);
  207|  1.75k|      class_tag = ASN1_Class(b & 0xE0);
  208|       |      // The EOC marker is primitive; a constructed universal tag 0 has no
  209|       |      // valid meaning and would otherwise bypass the EOC handling, which
  210|       |      // matches on (Eoc, Universal) exactly
  211|  1.75k|      if(type_tag == ASN1_Type::Eoc && class_tag == ASN1_Class::Constructed) {
  ------------------
  |  Branch (211:10): [True: 294, False: 1.46k]
  |  Branch (211:40): [True: 1, False: 293]
  ------------------
  212|      1|         throw BER_Decoding_Error("EOC tag with constructed encoding");
  213|      1|      }
  214|  1.75k|      return 1;
  215|  1.75k|   }
  216|       |
  217|    165|   class_tag = ASN1_Class(b & 0xE0);
  218|    165|   size_t tag_bytes = 1;
  219|    165|   uint32_t tag_buf = 0;
  220|       |
  221|    535|   while(true) {
  ------------------
  |  Branch (221:10): [True: 535, Folded]
  ------------------
  222|    535|      if(src->peek(&b, 1, offset + tag_bytes) == 0) {
  ------------------
  |  Branch (222:10): [True: 5, False: 530]
  ------------------
  223|      5|         throw BER_Decoding_Error("Long-form tag truncated");
  224|      5|      }
  225|       |      // Reject if shifting in another 7 bits would overflow the uint32_t tag
  226|    530|      if((tag_buf >> 25) != 0) {
  ------------------
  |  Branch (226:10): [True: 9, False: 521]
  ------------------
  227|      9|         throw BER_Decoding_Error("Long-form tag overflowed 32 bits");
  228|      9|      }
  229|       |      // Required even by BER (X.690 section 8.1.2.4.2 sentence c).
  230|       |      // Bits 7-1 of the first subsequent octet must not be all zero; this rules
  231|       |      // out both 0x80 (continuation with no data) and 0x00 (a long-form encoding
  232|       |      // of tag value 0, which collides with the EOC marker).
  233|    521|      if(tag_bytes == 1 && (b & 0x7F) == 0) {
  ------------------
  |  Branch (233:10): [True: 163, False: 358]
  |  Branch (233:28): [True: 1, False: 162]
  ------------------
  234|      1|         throw BER_Decoding_Error("Long form tag with leading zero");
  235|      1|      }
  236|    520|      ++tag_bytes;
  237|    520|      tag_buf = (tag_buf << 7) | (b & 0x7F);
  238|    520|      if((b & 0x80) == 0) {
  ------------------
  |  Branch (238:10): [True: 150, False: 370]
  ------------------
  239|    150|         break;
  240|    150|      }
  241|    520|   }
  242|       |
  243|       |   // Per X.690 8.1.2.2, tag values 0-30 shall be encoded in the short form.
  244|       |   // Long-form encoding is reserved for tag values >= 31 (X.690 8.1.2.3).
  245|       |   // This is unconditional and applies to BER as well as DER.
  246|    150|   if(tag_buf <= 30) {
  ------------------
  |  Branch (246:7): [True: 4, False: 146]
  ------------------
  247|      4|      throw BER_Decoding_Error("Long-form tag encoding used for small tag value");
  248|      4|   }
  249|       |
  250|    146|   if(tag_buf == static_cast<uint32_t>(ASN1_Type::NoObject)) {
  ------------------
  |  Branch (250:7): [True: 1, False: 145]
  ------------------
  251|      1|      throw BER_Decoding_Error("Tag value collides with internal sentinel");
  252|      1|   }
  253|       |
  254|       |   // NOLINTNEXTLINE(clang-analyzer-optin.core.EnumCastOutOfRange)
  255|    145|   type_tag = ASN1_Type(tag_buf);
  256|    145|   return tag_bytes;
  257|    146|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_111peek_lengthEPNS_10DataSourceEmRmmbb:
  265|  1.90k|   DataSource* src, size_t offset, size_t& field_size, size_t allow_indef, bool constructed, bool der_mode) {
  266|  1.90k|   uint8_t b = 0;
  267|  1.90k|   if(src->peek(&b, 1, offset) == 0) {
  ------------------
  |  Branch (267:7): [True: 9, False: 1.89k]
  ------------------
  268|      9|      throw BER_Decoding_Error("Length field not found");
  269|      9|   }
  270|       |
  271|  1.89k|   field_size = 1;
  272|  1.89k|   if((b & 0x80) == 0) {
  ------------------
  |  Branch (272:7): [True: 1.79k, False: 99]
  ------------------
  273|  1.79k|      return b;
  274|  1.79k|   }
  275|       |
  276|     99|   const size_t num_length_bytes = (b & 0x7F);
  277|     99|   field_size += num_length_bytes;
  278|     99|   if(field_size > 5) {
  ------------------
  |  Branch (278:7): [True: 19, False: 80]
  ------------------
  279|     19|      throw BER_Decoding_Error("Length field is too large");
  280|     19|   }
  281|       |
  282|     80|   if(num_length_bytes == 0) {
  ------------------
  |  Branch (282:7): [True: 1, False: 79]
  ------------------
  283|       |      // Indefinite length is not allowed in DER
  284|      1|      if(der_mode) {
  ------------------
  |  Branch (284:10): [True: 1, False: 0]
  ------------------
  285|      1|         throw BER_Decoding_Error("Detected indefinite-length encoding in DER structure");
  286|      1|      }
  287|       |      // Indefinite length is only valid for constructed types (X.690 8.1.3.2)
  288|      0|      if(!constructed) {
  ------------------
  |  Branch (288:10): [True: 0, False: 0]
  ------------------
  289|      0|         throw BER_Decoding_Error("Indefinite-length encoding used with non-constructed type");
  290|      0|      }
  291|      0|      if(allow_indef == 0) {
  ------------------
  |  Branch (291:10): [True: 0, False: 0]
  ------------------
  292|      0|         throw BER_Decoding_Error("Nested EOC markers too deep, rejecting to avoid stack exhaustion");
  293|      0|      }
  294|      0|      return find_eoc(src, offset + 1, allow_indef - 1);
  295|      0|   }
  296|       |
  297|     79|   size_t length = 0;
  298|    337|   for(size_t i = 0; i < num_length_bytes; ++i) {
  ------------------
  |  Branch (298:22): [True: 259, False: 78]
  ------------------
  299|    259|      if(src->peek(&b, 1, offset + 1 + i) == 0) {
  ------------------
  |  Branch (299:10): [True: 1, False: 258]
  ------------------
  300|      1|         throw BER_Decoding_Error("Corrupted length field");
  301|      1|      }
  302|    258|      if(get_byte<0>(length) != 0) {
  ------------------
  |  Branch (302:10): [True: 0, False: 258]
  ------------------
  303|      0|         throw BER_Decoding_Error("Field length overflow");
  304|      0|      }
  305|    258|      length = (length << 8) | b;
  306|    258|   }
  307|     78|   return length;
  308|     79|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_114is_constructedENS_10ASN1_ClassE:
   22|  53.0k|bool is_constructed(ASN1_Class class_tag) {
   23|  53.0k|   return (static_cast<uint32_t>(class_tag) & static_cast<uint32_t>(ASN1_Class::Constructed)) != 0;
   24|  53.0k|}
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_116BerDecodedLength14content_lengthEv:
  114|   165k|      size_t content_length() const { return m_content_length; }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_116BerDecodedLength17indefinite_lengthEv:
  121|  41.2k|      bool indefinite_length() const { return m_indefinite; }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_116BerDecodedLength12total_lengthEv:
  117|  41.3k|      size_t total_length() const { return m_indefinite ? m_content_length + 2 : m_content_length; }
  ------------------
  |  Branch (117:44): [True: 0, False: 41.3k]
  ------------------
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_120verify_set_is_sortedENSt3__14spanIKhLm18446744073709551615EEE:
  426|    795|void verify_set_is_sorted(std::span<const uint8_t> content) {
  427|    795|   DataSource_Span src(content);
  428|    795|   size_t offset = 0;
  429|    795|   std::optional<std::span<const uint8_t>> prev;
  430|       |
  431|  2.56k|   while(offset < content.size()) {
  ------------------
  |  Branch (431:10): [True: 1.92k, False: 639]
  ------------------
  432|  1.92k|      ASN1_Type type_tag = ASN1_Type::NoObject;
  433|  1.92k|      ASN1_Class class_tag = ASN1_Class::NoObject;
  434|  1.92k|      const size_t tag_size = peek_tag(&src, offset, type_tag, class_tag);
  435|       |
  436|  1.92k|      size_t length_size = 0;
  437|  1.92k|      const size_t item_size =
  438|  1.92k|         peek_length(&src, offset + tag_size, length_size, /*allow_indef=*/0, is_constructed(class_tag), true);
  439|       |
  440|  1.92k|      const auto end = checked_add(offset, tag_size, length_size, item_size);
  441|  1.92k|      if(!end || *end > content.size()) {
  ------------------
  |  Branch (441:10): [True: 51, False: 1.87k]
  |  Branch (441:18): [True: 85, False: 1.78k]
  ------------------
  442|     85|         throw BER_Decoding_Error("SET element exceeds available data");
  443|     85|      }
  444|       |
  445|  1.83k|      const auto elem = content.subspan(offset, *end - offset);
  446|  1.83k|      if(prev && std::lexicographical_compare(elem.begin(), elem.end(), prev->begin(), prev->end())) {
  ------------------
  |  Branch (446:10): [True: 1.03k, False: 804]
  |  Branch (446:18): [True: 71, False: 962]
  ------------------
  447|     71|         throw BER_Decoding_Error("Detected unsorted SET in DER structure");
  448|     71|      }
  449|  1.76k|      prev = elem;
  450|  1.76k|      offset = *end;
  451|  1.76k|   }
  452|    795|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_126asn1_bitstring_unused_bitsERKNS_10BER_ObjectENS_9ASN1_TypeENS_10ASN1_ClassEb:
  990|  4.72k|uint8_t asn1_bitstring_unused_bits(const BER_Object& obj, ASN1_Type type_tag, ASN1_Class class_tag, bool require_der) {
  991|  4.72k|   obj.assert_is_a(type_tag, class_tag);
  992|  4.72k|   BOTAN_ASSERT_NOMSG(!is_constructed(obj));
  ------------------
  |  |   84|  4.72k|   do {                                                                     \
  |  |   85|  4.72k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  4.72k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 4.72k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  4.72k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 4.72k]
  |  |  ------------------
  ------------------
  993|       |
  994|  4.72k|   if(obj.length() == 0) {
  ------------------
  |  Branch (994:7): [True: 1, False: 4.72k]
  ------------------
  995|      1|      throw BER_Decoding_Error("Invalid BIT STRING");
  996|      1|   }
  997|       |
  998|  4.72k|   const uint8_t unused_bits = obj.bits()[0];
  999|       |
 1000|  4.72k|   if(unused_bits >= 8) {
  ------------------
  |  Branch (1000:7): [True: 5, False: 4.72k]
  ------------------
 1001|      5|      throw BER_Decoding_Error("Invalid number of unused bits in BIT STRING");
 1002|      5|   }
 1003|       |
 1004|  4.72k|   if(obj.length() == 1 && unused_bits != 0) {
  ------------------
  |  Branch (1004:7): [True: 286, False: 4.43k]
  |  Branch (1004:28): [True: 2, False: 284]
  ------------------
 1005|      2|      throw BER_Decoding_Error("Invalid BIT STRING");
 1006|      2|   }
 1007|       |
 1008|  4.72k|   if(require_der && unused_bits > 0) {
  ------------------
  |  Branch (1008:7): [True: 4.71k, False: 2]
  |  Branch (1008:22): [True: 7, False: 4.71k]
  ------------------
 1009|      7|      const uint8_t last_byte = obj.bits()[obj.length() - 1];
 1010|      7|      if((last_byte & ((1 << unused_bits) - 1)) != 0) {
  ------------------
  |  Branch (1010:10): [True: 2, False: 5]
  ------------------
 1011|      2|         throw BER_Decoding_Error("Detected non-zero padding bits in BIT STRING in DER structure");
 1012|      2|      }
 1013|      7|   }
 1014|       |
 1015|  4.71k|   return unused_bits;
 1016|  4.72k|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_114is_constructedERKNS_10BER_ObjectE:
  838|  4.74k|bool is_constructed(const BER_Object& obj) {
  839|  4.74k|   return is_constructed(obj.class_tag());
  840|  4.74k|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_115DataSource_SpanC2ENSt3__14spanIKhLm18446744073709551615EEE:
  414|  1.18k|      explicit DataSource_Span(std::span<const uint8_t> buf) : m_buf(buf) {}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_115DataSource_Span4readEPhm:
  392|    925|      size_t read(uint8_t out[], size_t length) override {
  393|    925|         const size_t got = std::min(m_buf.size() - m_offset, length);
  394|    925|         copy_mem(out, m_buf.data() + m_offset, got);
  395|    925|         m_offset += got;
  396|    925|         return got;
  397|    925|      }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_115DataSource_Span4peekEPhmm:
  399|  4.61k|      size_t peek(uint8_t out[], size_t length, size_t peek_offset) const override {
  400|  4.61k|         if(peek_offset >= m_buf.size() - m_offset) {
  ------------------
  |  Branch (400:13): [True: 15, False: 4.60k]
  ------------------
  401|     15|            return 0;
  402|     15|         }
  403|  4.60k|         const size_t got = std::min(m_buf.size() - m_offset - peek_offset, length);
  404|  4.60k|         copy_mem(out, m_buf.data() + m_offset + peek_offset, got);
  405|  4.60k|         return got;
  406|  4.61k|      }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_116BerDecodedLength12field_lengthEv:
  119|     77|      size_t field_length() const { return m_field_length; }
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_120DataSource_BERObjectC2EONS_10BER_ObjectE:
  379|  20.4k|      explicit DataSource_BERObject(BER_Object&& obj) : m_obj(std::move(obj)) {}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_120DataSource_BERObject4readEPhm:
  349|  88.8k|      size_t read(uint8_t out[], size_t length) override {
  350|  88.8k|         BOTAN_ASSERT_NOMSG(m_offset <= m_obj.length());
  ------------------
  |  |   84|  88.8k|   do {                                                                     \
  |  |   85|  88.8k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  88.8k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 88.8k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  88.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 88.8k]
  |  |  ------------------
  ------------------
  351|  88.8k|         const size_t got = std::min<size_t>(m_obj.length() - m_offset, length);
  352|  88.8k|         copy_mem(out, m_obj.bits() + m_offset, got);
  353|  88.8k|         m_offset += got;
  354|  88.8k|         return got;
  355|  88.8k|      }
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_120DataSource_BERObject15check_availableEm:
  370|  22.7k|      bool check_available(size_t n) override {
  371|  22.7k|         BOTAN_ASSERT_NOMSG(m_offset <= m_obj.length());
  ------------------
  |  |   84|  22.7k|   do {                                                                     \
  |  |   85|  22.7k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  22.7k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 22.7k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  22.7k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 22.7k]
  |  |  ------------------
  ------------------
  372|  22.7k|         return (n <= (m_obj.length() - m_offset));
  373|  22.7k|      }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_120DataSource_BERObject11end_of_dataEv:
  375|  20.5k|      bool end_of_data() const override { return get_bytes_read() == m_obj.length(); }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_120DataSource_BERObject14get_bytes_readEv:
  377|  20.5k|      size_t get_bytes_read() const override { return m_offset; }
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_125asn1_decode_binary_stringINSt3__19allocatorIhEEEEvRNS2_6vectorIhT_EERKNS_10BER_ObjectENS_9ASN1_TypeESC_NS_10ASN1_ClassERKNS_11BER_Decoder6LimitsE:
  932|     16|                               const BER_Decoder::Limits& limits) {
  933|       |   // DER requires BIT STRING and OCTET STRING to use primitive encoding;
  934|       |   // in BER the constructed (fragmented) form is decoded by concatenation
  935|     16|   if(is_constructed(obj)) {
  ------------------
  |  Branch (935:7): [True: 0, False: 16]
  ------------------
  936|      0|      obj.assert_is_a(type_tag, class_tag | ASN1_Class::Constructed);
  937|       |
  938|      0|      if(limits.require_der_encoding()) {
  ------------------
  |  Branch (938:10): [True: 0, False: 0]
  ------------------
  939|      0|         throw BER_Decoding_Error("Detected constructed string encoding in DER structure");
  940|      0|      }
  941|       |
  942|       |      // Concatenate into a temporary so a failed decode leaves buffer unmodified
  943|      0|      std::vector<uint8_t, Alloc> concat;
  944|      0|      concat.reserve(obj.length());  // upper possible bound on the output size
  945|      0|      if(real_type == ASN1_Type::OctetString) {
  ------------------
  |  Branch (945:10): [True: 0, False: 0]
  ------------------
  946|      0|         asn1_concat_constructed_octet_string(concat, obj, limits, 0);
  947|      0|      } else {
  948|      0|         asn1_concat_constructed_bit_string(concat, obj, limits, 0);
  949|      0|      }
  950|      0|      buffer = std::move(concat);
  951|      0|      return;
  952|      0|   }
  953|       |
  954|     16|   obj.assert_is_a(type_tag, class_tag);
  955|       |
  956|     16|   if(real_type == ASN1_Type::OctetString) {
  ------------------
  |  Branch (956:7): [True: 0, False: 16]
  ------------------
  957|      0|      buffer.assign(obj.bits(), obj.bits() + obj.length());
  958|     16|   } else {
  959|     16|      if(obj.length() == 0) {
  ------------------
  |  Branch (959:10): [True: 1, False: 15]
  ------------------
  960|      1|         throw BER_Decoding_Error("Invalid BIT STRING");
  961|      1|      }
  962|       |
  963|     15|      const uint8_t unused_bits = obj.bits()[0];
  964|       |
  965|     15|      if(unused_bits >= 8) {
  ------------------
  |  Branch (965:10): [True: 1, False: 14]
  ------------------
  966|      1|         throw BER_Decoding_Error("Bad number of unused bits in BIT STRING");
  967|      1|      }
  968|       |
  969|       |      // Empty BIT STRING with unused bits > 0 ...
  970|     14|      if(unused_bits > 0 && obj.length() < 2) {
  ------------------
  |  Branch (970:10): [True: 6, False: 8]
  |  Branch (970:29): [True: 2, False: 4]
  ------------------
  971|      2|         throw BER_Decoding_Error("Invalid BIT STRING");
  972|      2|      }
  973|       |
  974|       |      // DER requires unused bits in BIT STRING to be zero (X.690 section 11.2.2)
  975|     12|      if(limits.require_der_encoding() && unused_bits > 0) {
  ------------------
  |  Branch (975:10): [True: 12, False: 0]
  |  Branch (975:43): [True: 4, False: 8]
  ------------------
  976|      4|         const uint8_t last_byte = obj.bits()[obj.length() - 1];
  977|      4|         if((last_byte & ((1 << unused_bits) - 1)) != 0) {
  ------------------
  |  Branch (977:13): [True: 1, False: 3]
  ------------------
  978|      1|            throw BER_Decoding_Error("Detected non-zero padding bits in BIT STRING in DER structure");
  979|      1|         }
  980|      4|      }
  981|       |
  982|     11|      buffer.resize(obj.length() - 1);
  983|       |
  984|     11|      if(obj.length() > 1) {
  ------------------
  |  Branch (984:10): [True: 7, False: 4]
  ------------------
  985|      7|         copy_mem(buffer.data(), obj.bits() + 1, obj.length() - 1);
  986|      7|      }
  987|     11|   }
  988|     16|}

_ZN5Botan4ASN119der_sequence_headerEm:
   71|  4.00k|std::vector<uint8_t> der_sequence_header(size_t contents_len) {
   72|  4.00k|   std::vector<uint8_t> header;
   73|  4.00k|   header.reserve(2 + sizeof(contents_len));
   74|  4.00k|   encode_tag(header, ASN1_Type::Sequence, ASN1_Class::Constructed);
   75|  4.00k|   encode_length(header, contents_len);
   76|  4.00k|   return header;
   77|  4.00k|}
_ZN5Botan11DER_EncoderC2ERNSt3__16vectorIhNS1_9allocatorIhEEEE:
   89|  2.26k|DER_Encoder::DER_Encoder(std::vector<uint8_t>& vec) {
   90|  2.26k|   m_append_output = [&vec](const uint8_t b[], size_t l) {
   91|  2.26k|      if(l > 0) {
   92|  2.26k|         vec.insert(vec.end(), b, b + l);
   93|  2.26k|      }
   94|  2.26k|   };
   95|  2.26k|}
_ZN5Botan11DER_Encoder12DER_Sequence13push_contentsERS0_:
  100|  3.96k|void DER_Encoder::DER_Sequence::push_contents(DER_Encoder& der) {
  101|  3.96k|   const auto real_class_tag = m_class_tag | ASN1_Class::Constructed;
  102|       |
  103|  3.96k|   if(m_sort_contents) {
  ------------------
  |  Branch (103:7): [True: 0, False: 3.96k]
  ------------------
  104|      0|      std::sort(m_set_contents.begin(), m_set_contents.end());
  105|      0|      for(const auto& set_elem : m_set_contents) {
  ------------------
  |  Branch (105:32): [True: 0, False: 0]
  ------------------
  106|      0|         m_contents += set_elem;
  107|      0|      }
  108|      0|      m_set_contents.clear();
  109|      0|   }
  110|       |
  111|  3.96k|   der.add_object(m_type_tag, real_class_tag, m_contents.data(), m_contents.size());
  112|  3.96k|   m_contents.clear();
  113|  3.96k|}
_ZN5Botan11DER_Encoder12DER_Sequence9add_bytesEPKhm:
  118|  2.64k|void DER_Encoder::DER_Sequence::add_bytes(const uint8_t data[], size_t length) {
  119|  2.64k|   if(m_sort_contents) {
  ------------------
  |  Branch (119:7): [True: 0, False: 2.64k]
  ------------------
  120|      0|      if(length > 0) {
  ------------------
  |  Branch (120:10): [True: 0, False: 0]
  ------------------
  121|      0|         m_set_contents.emplace_back(data, data + length);
  122|      0|      } else {
  123|      0|         m_set_contents.emplace_back();
  124|      0|      }
  125|  2.64k|   } else {
  126|  2.64k|      m_contents += std::make_pair(data, length);
  127|  2.64k|   }
  128|  2.64k|}
_ZN5Botan11DER_Encoder12DER_Sequence9add_bytesEPKhmS3_m:
  130|  5.28k|void DER_Encoder::DER_Sequence::add_bytes(const uint8_t hdr[], size_t hdr_len, const uint8_t val[], size_t val_len) {
  131|  5.28k|   if(m_sort_contents) {
  ------------------
  |  Branch (131:7): [True: 0, False: 5.28k]
  ------------------
  132|      0|      secure_vector<uint8_t> m;
  133|      0|      m.reserve(hdr_len + val_len);
  134|      0|      m += std::make_pair(hdr, hdr_len);
  135|      0|      m += std::make_pair(val, val_len);
  136|      0|      m_set_contents.push_back(std::move(m));
  137|  5.28k|   } else {
  138|  5.28k|      m_contents += std::make_pair(hdr, hdr_len);
  139|  5.28k|      m_contents += std::make_pair(val, val_len);
  140|  5.28k|   }
  141|  5.28k|}
_ZN5Botan11DER_Encoder12DER_SequenceC2ENS_9ASN1_TypeENS_10ASN1_ClassEb:
  154|  3.96k|      m_type_tag(type_tag),
  155|  3.96k|      m_class_tag(class_tag),
  156|  3.96k|      m_sort_contents(sort_contents || (type_tag == ASN1_Type::Set && class_tag == ASN1_Class::Universal)) {}
  ------------------
  |  Branch (156:23): [True: 0, False: 3.96k]
  |  Branch (156:41): [True: 0, False: 3.96k]
  |  Branch (156:71): [True: 0, False: 0]
  ------------------
_ZN5Botan11DER_Encoder10start_consENS_9ASN1_TypeENS_10ASN1_ClassE:
  192|  3.96k|DER_Encoder& DER_Encoder::start_cons(ASN1_Type type_tag, ASN1_Class class_tag) {
  193|  3.96k|   return start_cons(type_tag, class_tag, false);
  194|  3.96k|}
_ZN5Botan11DER_Encoder10start_consENS_9ASN1_TypeENS_10ASN1_ClassEb:
  200|  3.96k|DER_Encoder& DER_Encoder::start_cons(ASN1_Type type_tag, ASN1_Class class_tag, bool sort_contents) {
  201|  3.96k|   m_subsequences.push_back(DER_Sequence(type_tag, class_tag, sort_contents));
  202|  3.96k|   return (*this);
  203|  3.96k|}
_ZN5Botan11DER_Encoder8end_consEv:
  208|  3.96k|DER_Encoder& DER_Encoder::end_cons() {
  209|  3.96k|   if(m_subsequences.empty()) {
  ------------------
  |  Branch (209:7): [True: 0, False: 3.96k]
  ------------------
  210|      0|      throw Invalid_State("DER_Encoder::end_cons: No such sequence");
  211|      0|   }
  212|       |
  213|  3.96k|   DER_Sequence last_seq = std::move(m_subsequences[m_subsequences.size() - 1]);
  214|  3.96k|   m_subsequences.pop_back();
  215|  3.96k|   last_seq.push_contents(*this);
  216|       |
  217|  3.96k|   return (*this);
  218|  3.96k|}
_ZN5Botan11DER_Encoder9raw_bytesEPKhm:
  237|  2.64k|DER_Encoder& DER_Encoder::raw_bytes(const uint8_t bytes[], size_t length) {
  238|  2.64k|   if(!m_subsequences.empty()) {
  ------------------
  |  Branch (238:7): [True: 2.64k, False: 0]
  ------------------
  239|  2.64k|      m_subsequences[m_subsequences.size() - 1].add_bytes(bytes, length);
  240|  2.64k|   } else if(m_append_output) {
  ------------------
  |  Branch (240:14): [True: 0, False: 0]
  ------------------
  241|      0|      m_append_output(bytes, length);
  242|      0|   } else {
  243|      0|      m_default_outbuf += std::make_pair(bytes, length);
  244|      0|   }
  245|       |
  246|  2.64k|   return (*this);
  247|  2.64k|}
_ZN5Botan11DER_Encoder10add_objectENS_9ASN1_TypeENS_10ASN1_ClassEPKhm:
  285|  7.54k|DER_Encoder& DER_Encoder::add_object(ASN1_Type type_tag, ASN1_Class class_tag, const uint8_t rep[], size_t length) {
  286|  7.54k|   std::vector<uint8_t> hdr;
  287|  7.54k|   encode_tag(hdr, type_tag, class_tag);
  288|  7.54k|   encode_length(hdr, length);
  289|       |
  290|  7.54k|   if(!m_subsequences.empty()) {
  ------------------
  |  Branch (290:7): [True: 5.28k, False: 2.26k]
  ------------------
  291|  5.28k|      m_subsequences[m_subsequences.size() - 1].add_bytes(hdr.data(), hdr.size(), rep, length);
  292|  5.28k|   } else if(m_append_output) {
  ------------------
  |  Branch (292:14): [True: 2.26k, False: 0]
  ------------------
  293|  2.26k|      m_append_output(hdr.data(), hdr.size());
  294|  2.26k|      m_append_output(rep, length);
  295|  2.26k|   } else {
  296|      0|      m_default_outbuf += hdr;
  297|      0|      m_default_outbuf += std::make_pair(rep, length);
  298|      0|   }
  299|       |
  300|  7.54k|   return (*this);
  301|  7.54k|}
_ZN5Botan4ASN116integer_contentsERKNS_6BigIntE:
  356|  1.96k|std::vector<uint8_t> ASN1::integer_contents(const BigInt& n) {
  357|  1.96k|   if(n == 0) {
  ------------------
  |  Branch (357:7): [True: 139, False: 1.82k]
  ------------------
  358|    139|      return {0x00};
  359|    139|   }
  360|       |
  361|       |   // Serialize magnitude with one extra leading byte
  362|  1.82k|   auto contents = n.serialize(n.bytes() + 1);
  363|       |
  364|  1.82k|   if(n.signum() < 0) {
  ------------------
  |  Branch (364:7): [True: 1.31k, False: 516]
  ------------------
  365|       |      // Two's complement: bitwise NOT then increment
  366|  3.88k|      for(auto& byte : contents) {
  ------------------
  |  Branch (366:22): [True: 3.88k, False: 1.31k]
  ------------------
  367|  3.88k|         byte = ~byte;
  368|  3.88k|      }
  369|  1.54k|      for(size_t i = contents.size(); i > 0; --i) {
  ------------------
  |  Branch (369:39): [True: 1.54k, False: 0]
  ------------------
  370|  1.54k|         if(++contents[i - 1] != 0) {
  ------------------
  |  Branch (370:13): [True: 1.31k, False: 238]
  ------------------
  371|  1.31k|            break;
  372|  1.31k|         }
  373|  1.54k|      }
  374|  1.31k|   }
  375|       |
  376|       |   /*
  377|       |   * DER requires the leading byte be emitted only if it required
  378|       |   */
  379|  1.82k|   BOTAN_ASSERT_NOMSG(contents.size() >= 2);
  ------------------
  |  |   84|  1.82k|   do {                                                                     \
  |  |   85|  1.82k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  1.82k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 1.82k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  1.82k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 1.82k]
  |  |  ------------------
  ------------------
  380|  1.82k|   const bool leading_byte_redundant =
  381|  1.82k|      (contents[0] == 0x00 && (contents[1] & 0x80) == 0) || (contents[0] == 0xFF && (contents[1] & 0x80) != 0);
  ------------------
  |  Branch (381:8): [True: 516, False: 1.31k]
  |  Branch (381:31): [True: 441, False: 75]
  |  Branch (381:62): [True: 1.31k, False: 75]
  |  Branch (381:85): [True: 1.29k, False: 15]
  ------------------
  382|       |
  383|  1.82k|   if(leading_byte_redundant) {
  ------------------
  |  Branch (383:7): [True: 1.73k, False: 90]
  ------------------
  384|  1.73k|      contents.erase(contents.begin());
  385|  1.73k|   }
  386|  1.82k|   return contents;
  387|  1.96k|}
_ZN5Botan11DER_Encoder16encode_bitstringENSt3__14spanIKhLm18446744073709551615EEEmNS_9ASN1_TypeENS_10ASN1_ClassE:
  414|  1.32k|                                           ASN1_Class class_tag) {
  415|  1.32k|   if(unused_bits >= 8) {
  ------------------
  |  Branch (415:7): [True: 0, False: 1.32k]
  ------------------
  416|      0|      throw Invalid_Argument("DER_Encoder: Invalid unused bit count for BIT STRING");
  417|      0|   }
  418|       |
  419|  1.32k|   if(bits.empty() && unused_bits != 0) {
  ------------------
  |  Branch (419:7): [True: 1, False: 1.32k]
  |  Branch (419:23): [True: 0, False: 1]
  ------------------
  420|      0|      throw Invalid_Argument("DER_Encoder: Empty BIT STRING cannot have unused bits");
  421|      0|   }
  422|       |
  423|  1.32k|   if(unused_bits > 0 && (bits.back() & ((1U << unused_bits) - 1)) != 0) {
  ------------------
  |  Branch (423:7): [True: 0, False: 1.32k]
  |  Branch (423:26): [True: 0, False: 0]
  ------------------
  424|      0|      throw Invalid_Argument("DER_Encoder: BIT STRING unused bits must be zero");
  425|      0|   }
  426|       |
  427|  1.32k|   secure_vector<uint8_t> encoded;
  428|  1.32k|   encoded.reserve(1 + bits.size());
  429|  1.32k|   encoded.push_back(static_cast<uint8_t>(unused_bits));
  430|  1.32k|   encoded.insert(encoded.end(), bits.begin(), bits.end());
  431|  1.32k|   return add_object(type_tag, class_tag, encoded);
  432|  1.32k|}
_ZN5Botan11DER_Encoder6encodeERKNS_11ASN1_ObjectE:
  467|  2.64k|DER_Encoder& DER_Encoder::encode(const ASN1_Object& obj) {
  468|  2.64k|   obj.encode_into(*this);
  469|  2.64k|   return (*this);
  470|  2.64k|}
der_enc.cpp:_ZN5Botan12_GLOBAL__N_110encode_tagERNSt3__16vectorIhNS1_9allocatorIhEEEENS_9ASN1_TypeENS_10ASN1_ClassE:
   26|  11.5k|void encode_tag(std::vector<uint8_t>& encoded_tag, ASN1_Type type_tag_e, ASN1_Class class_tag_e) {
   27|  11.5k|   const uint32_t type_tag = static_cast<uint32_t>(type_tag_e);
   28|  11.5k|   const uint32_t class_tag = static_cast<uint32_t>(class_tag_e);
   29|       |
   30|  11.5k|   if((class_tag | 0xE0) != 0xE0) {
  ------------------
  |  Branch (30:7): [True: 0, False: 11.5k]
  ------------------
   31|      0|      throw Encoding_Error(fmt("DER_Encoder: Invalid class tag {}", std::to_string(class_tag)));
   32|      0|   }
   33|       |
   34|  11.5k|   if(type_tag <= 30) {
  ------------------
  |  Branch (34:7): [True: 11.5k, False: 0]
  ------------------
   35|  11.5k|      encoded_tag.push_back(static_cast<uint8_t>(type_tag | class_tag));
   36|  11.5k|   } else {
   37|      0|      size_t blocks = high_bit(static_cast<uint32_t>(type_tag)) + 6;
   38|      0|      blocks = (blocks - (blocks % 7)) / 7;
   39|       |
   40|      0|      BOTAN_ASSERT_NOMSG(blocks > 0);
  ------------------
  |  |   84|      0|   do {                                                                     \
  |  |   85|      0|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|      0|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 0]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 0]
  |  |  ------------------
  ------------------
   41|       |
   42|      0|      encoded_tag.push_back(static_cast<uint8_t>(class_tag | 0x1F));
   43|      0|      for(size_t i = 0; i != blocks - 1; ++i) {
  ------------------
  |  Branch (43:25): [True: 0, False: 0]
  ------------------
   44|      0|         encoded_tag.push_back(0x80 | ((type_tag >> 7 * (blocks - i - 1)) & 0x7F));
   45|      0|      }
   46|      0|      encoded_tag.push_back(type_tag & 0x7F);
   47|      0|   }
   48|  11.5k|}
der_enc.cpp:_ZN5Botan12_GLOBAL__N_113encode_lengthERNSt3__16vectorIhNS1_9allocatorIhEEEEm:
   53|  11.5k|void encode_length(std::vector<uint8_t>& encoded_length, size_t length) {
   54|  11.5k|   if(length <= 127) {
  ------------------
  |  Branch (54:7): [True: 11.5k, False: 0]
  ------------------
   55|  11.5k|      encoded_length.push_back(static_cast<uint8_t>(length));
   56|  11.5k|   } else {
   57|      0|      const size_t bytes_needed = significant_bytes(length);
   58|       |
   59|      0|      encoded_length.push_back(static_cast<uint8_t>(0x80 | bytes_needed));
   60|       |
   61|      0|      for(size_t i = sizeof(length) - bytes_needed; i < sizeof(length); ++i) {
  ------------------
  |  Branch (61:53): [True: 0, False: 0]
  ------------------
   62|      0|         encoded_length.push_back(get_byte_var(i, length));
   63|      0|      }
   64|      0|   }
   65|  11.5k|}
der_enc.cpp:_ZZN5Botan11DER_EncoderC1ERNSt3__16vectorIhNS1_9allocatorIhEEEEENK3$_0clEPKhm:
   90|  4.52k|   m_append_output = [&vec](const uint8_t b[], size_t l) {
   91|  4.52k|      if(l > 0) {
  ------------------
  |  Branch (91:10): [True: 4.52k, False: 0]
  ------------------
   92|  4.52k|         vec.insert(vec.end(), b, b + l);
   93|  4.52k|      }
   94|  4.52k|   };

_ZN5Botan7OID_MapC2Ev:
   11|      1|OID_Map::OID_Map() {
   12|      1|   m_str2oid = OID_Map::load_str2oid_map();
   13|      1|   m_oid2str = OID_Map::load_oid2str_map();
   14|      1|}
_ZN5Botan7OID_Map15global_registryEv:
   16|  2.64k|OID_Map& OID_Map::global_registry() {
   17|  2.64k|   static OID_Map g_map;
   18|  2.64k|   return g_map;
   19|  2.64k|}
_ZN5Botan7OID_Map7oid2strERKNS_3OIDE:
   73|  1.32k|std::optional<std::string> OID_Map::oid2str(const OID& oid) {
   74|  1.32k|   if(auto name = lookup_static_oid(oid)) {
  ------------------
  |  Branch (74:12): [True: 0, False: 1.32k]
  ------------------
   75|      0|      return std::string(*name);
   76|      0|   }
   77|       |
   78|  1.32k|   const lock_guard_type<mutex_type> lock(m_mutex);
   79|       |
   80|  1.32k|   auto i = m_oid2str.find(oid);
   81|  1.32k|   if(i != m_oid2str.end()) {
  ------------------
  |  Branch (81:7): [True: 0, False: 1.32k]
  ------------------
   82|      0|      return i->second;
   83|      0|   }
   84|       |
   85|  1.32k|   return {};
   86|  1.32k|}
_ZN5Botan7OID_Map7str2oidENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   88|  1.32k|OID OID_Map::str2oid(std::string_view str) {
   89|  1.32k|   if(auto oid = lookup_static_oid_name(str)) {
  ------------------
  |  Branch (89:12): [True: 1.32k, False: 0]
  ------------------
   90|  1.32k|      return std::move(*oid);
   91|  1.32k|   }
   92|       |
   93|      0|   const lock_guard_type<mutex_type> lock(m_mutex);
   94|      0|   auto i = m_str2oid.find(std::string(str));
   95|      0|   if(i != m_str2oid.end()) {
  ------------------
  |  Branch (95:7): [True: 0, False: 0]
  ------------------
   96|      0|      return i->second;
   97|      0|   }
   98|       |
   99|      0|   return OID();
  100|      0|}

_ZN5Botan7OID_Map17lookup_static_oidERKNS_3OIDE:
   48|  1.32k|std::optional<std::string_view> OID_Map::lookup_static_oid(const OID& oid) {
   49|  1.32k|   const uint32_t hc = static_cast<uint32_t>(oid.hash_code() % 858701);
   50|       |
   51|  1.32k|   switch(hc) {
   52|      1|      case 0x01506:
  ------------------
  |  Branch (52:7): [True: 1, False: 1.32k]
  ------------------
   53|      1|         return if_match(oid, {1, 2, 840, 10045, 4, 3, 1}, "ECDSA/SHA-224");
   54|      1|      case 0x01507:
  ------------------
  |  Branch (54:7): [True: 1, False: 1.32k]
  ------------------
   55|      1|         return if_match(oid, {1, 2, 840, 10045, 4, 3, 2}, "ECDSA/SHA-256");
   56|      1|      case 0x01508:
  ------------------
  |  Branch (56:7): [True: 1, False: 1.32k]
  ------------------
   57|      1|         return if_match(oid, {1, 2, 840, 10045, 4, 3, 3}, "ECDSA/SHA-384");
   58|      1|      case 0x01509:
  ------------------
  |  Branch (58:7): [True: 1, False: 1.32k]
  ------------------
   59|      1|         return if_match(oid, {1, 2, 840, 10045, 4, 3, 4}, "ECDSA/SHA-512");
   60|      1|      case 0x04C1E:
  ------------------
  |  Branch (60:7): [True: 1, False: 1.32k]
  ------------------
   61|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 3029, 1, 2, 1}, "ElGamal");
   62|      1|      case 0x04E61:
  ------------------
  |  Branch (62:7): [True: 1, False: 1.32k]
  ------------------
   63|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 3029, 1, 5, 1}, "OpenPGP.Curve25519");
   64|      1|      case 0x0779B:
  ------------------
  |  Branch (64:7): [True: 1, False: 1.32k]
  ------------------
   65|      1|         return if_match(oid, {1, 2, 840, 113549, 2, 5}, "MD5");
   66|      1|      case 0x0779D:
  ------------------
  |  Branch (66:7): [True: 1, False: 1.32k]
  ------------------
   67|      1|         return if_match(oid, {1, 2, 840, 113549, 2, 7}, "HMAC(SHA-1)");
   68|      1|      case 0x0779E:
  ------------------
  |  Branch (68:7): [True: 1, False: 1.32k]
  ------------------
   69|      1|         return if_match(oid, {1, 2, 840, 113549, 2, 8}, "HMAC(SHA-224)");
   70|      1|      case 0x0779F:
  ------------------
  |  Branch (70:7): [True: 1, False: 1.32k]
  ------------------
   71|      1|         return if_match(oid, {1, 2, 840, 113549, 2, 9}, "HMAC(SHA-256)");
   72|      1|      case 0x077A0:
  ------------------
  |  Branch (72:7): [True: 1, False: 1.32k]
  ------------------
   73|      1|         return if_match(oid, {1, 2, 840, 113549, 2, 10}, "HMAC(SHA-384)");
   74|      1|      case 0x077A1:
  ------------------
  |  Branch (74:7): [True: 1, False: 1.32k]
  ------------------
   75|      1|         return if_match(oid, {1, 2, 840, 113549, 2, 11}, "HMAC(SHA-512)");
   76|      1|      case 0x077A3:
  ------------------
  |  Branch (76:7): [True: 1, False: 1.32k]
  ------------------
   77|      1|         return if_match(oid, {1, 2, 840, 113549, 2, 13}, "HMAC(SHA-512-256)");
   78|      1|      case 0x0785E:
  ------------------
  |  Branch (78:7): [True: 1, False: 1.32k]
  ------------------
   79|      1|         return if_match(oid, {1, 2, 840, 113549, 3, 7}, "TripleDES/CBC");
   80|      1|      case 0x0C904:
  ------------------
  |  Branch (80:7): [True: 1, False: 1.32k]
  ------------------
   81|      1|         return if_match(oid, {1, 0, 14888, 3, 0, 5}, "ECKCDSA");
   82|      1|      case 0x11547:
  ------------------
  |  Branch (82:7): [True: 1, False: 1.32k]
  ------------------
   83|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 1}, "SphincsPlus-shake-128s-r3.1");
   84|      1|      case 0x11548:
  ------------------
  |  Branch (84:7): [True: 1, False: 1.32k]
  ------------------
   85|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 2}, "SphincsPlus-shake-128f-r3.1");
   86|      1|      case 0x11549:
  ------------------
  |  Branch (86:7): [True: 1, False: 1.32k]
  ------------------
   87|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 3}, "SphincsPlus-shake-192s-r3.1");
   88|      1|      case 0x1154A:
  ------------------
  |  Branch (88:7): [True: 1, False: 1.32k]
  ------------------
   89|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 4}, "SphincsPlus-shake-192f-r3.1");
   90|      1|      case 0x1154B:
  ------------------
  |  Branch (90:7): [True: 1, False: 1.32k]
  ------------------
   91|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 5}, "SphincsPlus-shake-256s-r3.1");
   92|      1|      case 0x1154C:
  ------------------
  |  Branch (92:7): [True: 1, False: 1.32k]
  ------------------
   93|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 6}, "SphincsPlus-shake-256f-r3.1");
   94|      1|      case 0x11608:
  ------------------
  |  Branch (94:7): [True: 1, False: 1.32k]
  ------------------
   95|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 1}, "SphincsPlus-sha2-128s-r3.1");
   96|      1|      case 0x11609:
  ------------------
  |  Branch (96:7): [True: 1, False: 1.32k]
  ------------------
   97|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 2}, "SphincsPlus-sha2-128f-r3.1");
   98|      1|      case 0x1160A:
  ------------------
  |  Branch (98:7): [True: 1, False: 1.32k]
  ------------------
   99|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 3}, "SphincsPlus-sha2-192s-r3.1");
  100|      1|      case 0x1160B:
  ------------------
  |  Branch (100:7): [True: 1, False: 1.32k]
  ------------------
  101|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 4}, "SphincsPlus-sha2-192f-r3.1");
  102|      1|      case 0x1160C:
  ------------------
  |  Branch (102:7): [True: 1, False: 1.32k]
  ------------------
  103|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 5}, "SphincsPlus-sha2-256s-r3.1");
  104|      1|      case 0x1160D:
  ------------------
  |  Branch (104:7): [True: 1, False: 1.32k]
  ------------------
  105|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 6}, "SphincsPlus-sha2-256f-r3.1");
  106|      1|      case 0x116C9:
  ------------------
  |  Branch (106:7): [True: 1, False: 1.32k]
  ------------------
  107|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 1}, "SphincsPlus-haraka-128s-r3.1");
  108|      1|      case 0x116CA:
  ------------------
  |  Branch (108:7): [True: 1, False: 1.32k]
  ------------------
  109|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 2}, "SphincsPlus-haraka-128f-r3.1");
  110|      1|      case 0x116CB:
  ------------------
  |  Branch (110:7): [True: 1, False: 1.32k]
  ------------------
  111|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 3}, "SphincsPlus-haraka-192s-r3.1");
  112|      1|      case 0x116CC:
  ------------------
  |  Branch (112:7): [True: 1, False: 1.32k]
  ------------------
  113|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 4}, "SphincsPlus-haraka-192f-r3.1");
  114|      1|      case 0x116CD:
  ------------------
  |  Branch (114:7): [True: 1, False: 1.32k]
  ------------------
  115|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 5}, "SphincsPlus-haraka-256s-r3.1");
  116|      1|      case 0x116CE:
  ------------------
  |  Branch (116:7): [True: 1, False: 1.32k]
  ------------------
  117|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 6}, "SphincsPlus-haraka-256f-r3.1");
  118|      1|      case 0x1533B:
  ------------------
  |  Branch (118:7): [True: 1, False: 1.32k]
  ------------------
  119|      1|         return if_match(oid, {1, 2, 156, 10197, 1, 104, 2}, "SM4/CBC");
  120|      1|      case 0x15341:
  ------------------
  |  Branch (120:7): [True: 1, False: 1.32k]
  ------------------
  121|      1|         return if_match(oid, {1, 2, 156, 10197, 1, 104, 8}, "SM4/GCM");
  122|      1|      case 0x1539D:
  ------------------
  |  Branch (122:7): [True: 1, False: 1.32k]
  ------------------
  123|      1|         return if_match(oid, {1, 2, 156, 10197, 1, 104, 100}, "SM4/OCB");
  124|      1|      case 0x187D7:
  ------------------
  |  Branch (124:7): [True: 1, False: 1.32k]
  ------------------
  125|      1|         return if_match(oid, {1, 3, 14, 3, 2, 7}, "DES/CBC");
  126|      1|      case 0x187EA:
  ------------------
  |  Branch (126:7): [True: 1, False: 1.32k]
  ------------------
  127|      1|         return if_match(oid, {1, 3, 14, 3, 2, 26}, "SHA-1");
  128|      1|      case 0x19933:
  ------------------
  |  Branch (128:7): [True: 1, False: 1.32k]
  ------------------
  129|      1|         return if_match(oid, {1, 3, 132, 0, 8}, "secp160r1");
  130|      1|      case 0x19934:
  ------------------
  |  Branch (130:7): [True: 1, False: 1.32k]
  ------------------
  131|      1|         return if_match(oid, {1, 3, 132, 0, 9}, "secp160k1");
  132|      1|      case 0x19935:
  ------------------
  |  Branch (132:7): [True: 1, False: 1.32k]
  ------------------
  133|      1|         return if_match(oid, {1, 3, 132, 0, 10}, "secp256k1");
  134|      1|      case 0x19949:
  ------------------
  |  Branch (134:7): [True: 1, False: 1.32k]
  ------------------
  135|      1|         return if_match(oid, {1, 3, 132, 0, 30}, "secp160r2");
  136|      1|      case 0x1994A:
  ------------------
  |  Branch (136:7): [True: 1, False: 1.32k]
  ------------------
  137|      1|         return if_match(oid, {1, 3, 132, 0, 31}, "secp192k1");
  138|      1|      case 0x1994B:
  ------------------
  |  Branch (138:7): [True: 1, False: 1.32k]
  ------------------
  139|      1|         return if_match(oid, {1, 3, 132, 0, 32}, "secp224k1");
  140|      1|      case 0x1994C:
  ------------------
  |  Branch (140:7): [True: 1, False: 1.32k]
  ------------------
  141|      1|         return if_match(oid, {1, 3, 132, 0, 33}, "secp224r1");
  142|      1|      case 0x1994D:
  ------------------
  |  Branch (142:7): [True: 1, False: 1.32k]
  ------------------
  143|      1|         return if_match(oid, {1, 3, 132, 0, 34}, "secp384r1");
  144|      1|      case 0x1994E:
  ------------------
  |  Branch (144:7): [True: 1, False: 1.32k]
  ------------------
  145|      1|         return if_match(oid, {1, 3, 132, 0, 35}, "secp521r1");
  146|      1|      case 0x199F8:
  ------------------
  |  Branch (146:7): [True: 1, False: 1.32k]
  ------------------
  147|      1|         return if_match(oid, {1, 3, 132, 1, 12}, "ECDH");
  148|      1|      case 0x1E7BF:
  ------------------
  |  Branch (148:7): [True: 1, False: 1.32k]
  ------------------
  149|      1|         return if_match(oid, {1, 2, 156, 10197, 1, 301, 1}, "SM2");
  150|      1|      case 0x1E7C0:
  ------------------
  |  Branch (150:7): [True: 1, False: 1.32k]
  ------------------
  151|      1|         return if_match(oid, {1, 2, 156, 10197, 1, 301, 2}, "SM2_Kex");
  152|      1|      case 0x1E7C1:
  ------------------
  |  Branch (152:7): [True: 1, False: 1.32k]
  ------------------
  153|      1|         return if_match(oid, {1, 2, 156, 10197, 1, 301, 3}, "SM2_Enc");
  154|      1|      case 0x21960:
  ------------------
  |  Branch (154:7): [True: 1, False: 1.32k]
  ------------------
  155|      1|         return if_match(oid, {1, 3, 36, 3, 3, 1, 2}, "RSA/PKCS1v15(RIPEMD-160)");
  156|      1|      case 0x2198A:
  ------------------
  |  Branch (156:7): [True: 1, False: 1.32k]
  ------------------
  157|      1|         return if_match(oid, {1, 2, 840, 113533, 7, 66, 10}, "CAST-128/CBC");
  158|      1|      case 0x2198F:
  ------------------
  |  Branch (158:7): [True: 1, False: 1.32k]
  ------------------
  159|      1|         return if_match(oid, {1, 2, 840, 113533, 7, 66, 15}, "KeyWrap.CAST-128");
  160|      0|      case 0x227C0:
  ------------------
  |  Branch (160:7): [True: 0, False: 1.32k]
  ------------------
  161|      0|         return if_match(oid, {1, 3, 101, 110}, "X25519");
  162|      1|      case 0x227C1:
  ------------------
  |  Branch (162:7): [True: 1, False: 1.32k]
  ------------------
  163|      1|         return if_match(oid, {1, 3, 101, 111}, "X448");
  164|      1|      case 0x227C2:
  ------------------
  |  Branch (164:7): [True: 1, False: 1.32k]
  ------------------
  165|      1|         return if_match(oid, {1, 3, 101, 112}, "Ed25519");
  166|      1|      case 0x227C3:
  ------------------
  |  Branch (166:7): [True: 1, False: 1.32k]
  ------------------
  167|      1|         return if_match(oid, {1, 3, 101, 113}, "Ed448");
  168|      1|      case 0x27565:
  ------------------
  |  Branch (168:7): [True: 1, False: 1.32k]
  ------------------
  169|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 48, 1, 1}, "PKIX.OCSP.BasicResponse");
  170|      1|      case 0x27566:
  ------------------
  |  Branch (170:7): [True: 1, False: 1.32k]
  ------------------
  171|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 48, 1, 2}, "PKIX.OCSP.Nonce");
  172|      1|      case 0x27569:
  ------------------
  |  Branch (172:7): [True: 1, False: 1.32k]
  ------------------
  173|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 48, 1, 5}, "PKIX.OCSP.NoCheck");
  174|      1|      case 0x29F7C:
  ------------------
  |  Branch (174:7): [True: 1, False: 1.32k]
  ------------------
  175|      1|         return if_match(oid, {1, 2, 410, 200004, 1, 100, 4, 3}, "ECKCDSA/SHA-1");
  176|      1|      case 0x29F7D:
  ------------------
  |  Branch (176:7): [True: 1, False: 1.32k]
  ------------------
  177|      1|         return if_match(oid, {1, 2, 410, 200004, 1, 100, 4, 4}, "ECKCDSA/SHA-224");
  178|      1|      case 0x29F7E:
  ------------------
  |  Branch (178:7): [True: 1, False: 1.32k]
  ------------------
  179|      1|         return if_match(oid, {1, 2, 410, 200004, 1, 100, 4, 5}, "ECKCDSA/SHA-256");
  180|      1|      case 0x2AC3B:
  ------------------
  |  Branch (180:7): [True: 1, False: 1.32k]
  ------------------
  181|      1|         return if_match(oid, {2, 5, 29, 32, 0}, "X509v3.AnyPolicy");
  182|      1|      case 0x2B000:
  ------------------
  |  Branch (182:7): [True: 1, False: 1.32k]
  ------------------
  183|      1|         return if_match(oid, {2, 5, 29, 37, 0}, "X509v3.AnyExtendedKeyUsage");
  184|      1|      case 0x2B5C9:
  ------------------
  |  Branch (184:7): [True: 1, False: 1.32k]
  ------------------
  185|      1|         return if_match(oid, {1, 2, 840, 10045, 2, 1}, "ECDSA");
  186|      1|      case 0x2B74B:
  ------------------
  |  Branch (186:7): [True: 1, False: 1.32k]
  ------------------
  187|      1|         return if_match(oid, {1, 2, 840, 10045, 4, 1}, "ECDSA/SHA-1");
  188|      1|      case 0x3474A:
  ------------------
  |  Branch (188:7): [True: 1, False: 1.32k]
  ------------------
  189|      1|         return if_match(oid, {1, 2, 840, 10046, 2, 1}, "DH");
  190|      1|      case 0x38D6D:
  ------------------
  |  Branch (190:7): [True: 1, False: 1.32k]
  ------------------
  191|      1|         return if_match(oid, {1, 2, 643, 7, 1, 2, 1, 1, 1}, "gost_256A");
  192|      1|      case 0x38D6E:
  ------------------
  |  Branch (192:7): [True: 1, False: 1.32k]
  ------------------
  193|      1|         return if_match(oid, {1, 2, 643, 7, 1, 2, 1, 1, 2}, "gost_256B");
  194|      1|      case 0x38E2E:
  ------------------
  |  Branch (194:7): [True: 1, False: 1.32k]
  ------------------
  195|      1|         return if_match(oid, {1, 2, 643, 7, 1, 2, 1, 2, 1}, "gost_512A");
  196|      1|      case 0x38E2F:
  ------------------
  |  Branch (196:7): [True: 1, False: 1.32k]
  ------------------
  197|      1|         return if_match(oid, {1, 2, 643, 7, 1, 2, 1, 2, 2}, "gost_512B");
  198|      1|      case 0x38F2C:
  ------------------
  |  Branch (198:7): [True: 1, False: 1.32k]
  ------------------
  199|      1|         return if_match(oid, {1, 2, 643, 2, 2, 3}, "GOST-34.10/GOST-R-34.11-94");
  200|      1|      case 0x38F3C:
  ------------------
  |  Branch (200:7): [True: 1, False: 1.32k]
  ------------------
  201|      1|         return if_match(oid, {1, 2, 643, 2, 2, 19}, "GOST-34.10");
  202|      1|      case 0x3D7B8:
  ------------------
  |  Branch (202:7): [True: 1, False: 1.32k]
  ------------------
  203|      1|         return if_match(oid, {0, 3, 4401, 5, 3, 1, 9, 6}, "Camellia-128/GCM");
  204|      1|      case 0x3D7CC:
  ------------------
  |  Branch (204:7): [True: 1, False: 1.32k]
  ------------------
  205|      1|         return if_match(oid, {0, 3, 4401, 5, 3, 1, 9, 26}, "Camellia-192/GCM");
  206|      1|      case 0x3D7E0:
  ------------------
  |  Branch (206:7): [True: 1, False: 1.32k]
  ------------------
  207|      1|         return if_match(oid, {0, 3, 4401, 5, 3, 1, 9, 46}, "Camellia-256/GCM");
  208|      1|      case 0x3F20F:
  ------------------
  |  Branch (208:7): [True: 1, False: 1.32k]
  ------------------
  209|      1|         return if_match(oid, {1, 3, 36, 3, 2, 1}, "RIPEMD-160");
  210|      1|      case 0x4266E:
  ------------------
  |  Branch (210:7): [True: 1, False: 1.32k]
  ------------------
  211|      1|         return if_match(oid, {0, 4, 0, 127, 0, 15, 1, 1, 13, 0}, "XMSS");
  212|      1|      case 0x478C4:
  ------------------
  |  Branch (212:7): [True: 1, False: 1.32k]
  ------------------
  213|      1|         return if_match(oid, {1, 2, 410, 200004, 1, 4}, "SEED/CBC");
  214|      1|      case 0x47D98:
  ------------------
  |  Branch (214:7): [True: 1, False: 1.32k]
  ------------------
  215|      1|         return if_match(oid, {1, 2, 156, 10197, 1, 301}, "sm2p256v1");
  216|      1|      case 0x47DFC:
  ------------------
  |  Branch (216:7): [True: 1, False: 1.32k]
  ------------------
  217|      1|         return if_match(oid, {1, 2, 156, 10197, 1, 401}, "SM3");
  218|      1|      case 0x47E60:
  ------------------
  |  Branch (218:7): [True: 1, False: 1.32k]
  ------------------
  219|      1|         return if_match(oid, {1, 2, 156, 10197, 1, 501}, "SM2_Sig/SM3");
  220|      1|      case 0x47E63:
  ------------------
  |  Branch (220:7): [True: 1, False: 1.32k]
  ------------------
  221|      1|         return if_match(oid, {1, 2, 156, 10197, 1, 504}, "RSA/PKCS1v15(SM3)");
  222|      1|      case 0x52B13:
  ------------------
  |  Branch (222:7): [True: 1, False: 1.32k]
  ------------------
  223|      1|         return if_match(oid, {1, 2, 643, 3, 131, 1, 1}, "GOST.INN");
  224|      1|      case 0x635AE:
  ------------------
  |  Branch (224:7): [True: 1, False: 1.32k]
  ------------------
  225|      1|         return if_match(oid, {1, 2, 250, 1, 223, 101, 256, 1}, "frp256v1");
  226|      1|      case 0x6A784:
  ------------------
  |  Branch (226:7): [True: 1, False: 1.32k]
  ------------------
  227|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 12, 10, 1, 1}, "PKCS12.KeyBag");
  228|      1|      case 0x6A785:
  ------------------
  |  Branch (228:7): [True: 1, False: 1.32k]
  ------------------
  229|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 12, 10, 1, 2}, "PKCS12.PKCS8ShroudedKeyBag");
  230|      1|      case 0x6A786:
  ------------------
  |  Branch (230:7): [True: 1, False: 1.32k]
  ------------------
  231|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 12, 10, 1, 3}, "PKCS12.CertBag");
  232|      1|      case 0x6A787:
  ------------------
  |  Branch (232:7): [True: 1, False: 1.32k]
  ------------------
  233|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 12, 10, 1, 4}, "PKCS12.CRLBag");
  234|      1|      case 0x6A788:
  ------------------
  |  Branch (234:7): [True: 1, False: 1.32k]
  ------------------
  235|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 12, 10, 1, 5}, "PKCS12.SecretBag");
  236|      1|      case 0x6A789:
  ------------------
  |  Branch (236:7): [True: 1, False: 1.32k]
  ------------------
  237|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 12, 10, 1, 6}, "PKCS12.SafeContentsBag");
  238|      1|      case 0x6EB86:
  ------------------
  |  Branch (238:7): [True: 1, False: 1.32k]
  ------------------
  239|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 6, 1}, "GOST-34.10-2012-256/SHA-256");
  240|      1|      case 0x6EC47:
  ------------------
  |  Branch (240:7): [True: 1, False: 1.32k]
  ------------------
  241|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 7, 1}, "Kyber-512-r3");
  242|      1|      case 0x6EC48:
  ------------------
  |  Branch (242:7): [True: 1, False: 1.32k]
  ------------------
  243|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 7, 2}, "Kyber-768-r3");
  244|      1|      case 0x6EC49:
  ------------------
  |  Branch (244:7): [True: 1, False: 1.32k]
  ------------------
  245|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 7, 3}, "Kyber-1024-r3");
  246|      1|      case 0x6EDC9:
  ------------------
  |  Branch (246:7): [True: 1, False: 1.32k]
  ------------------
  247|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 9, 1}, "Dilithium-4x4-r3");
  248|      1|      case 0x6EDCA:
  ------------------
  |  Branch (248:7): [True: 1, False: 1.32k]
  ------------------
  249|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 9, 2}, "Dilithium-6x5-r3");
  250|      1|      case 0x6EDCB:
  ------------------
  |  Branch (250:7): [True: 1, False: 1.32k]
  ------------------
  251|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 9, 3}, "Dilithium-8x7-r3");
  252|      1|      case 0x6EE8A:
  ------------------
  |  Branch (252:7): [True: 1, False: 1.32k]
  ------------------
  253|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 10, 1}, "Dilithium-4x4-AES-r3");
  254|      1|      case 0x6EE8B:
  ------------------
  |  Branch (254:7): [True: 1, False: 1.32k]
  ------------------
  255|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 10, 2}, "Dilithium-6x5-AES-r3");
  256|      1|      case 0x6EE8C:
  ------------------
  |  Branch (256:7): [True: 1, False: 1.32k]
  ------------------
  257|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 10, 3}, "Dilithium-8x7-AES-r3");
  258|      1|      case 0x6EF4B:
  ------------------
  |  Branch (258:7): [True: 1, False: 1.32k]
  ------------------
  259|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 11, 1}, "Kyber-512-90s-r3");
  260|      1|      case 0x6EF4C:
  ------------------
  |  Branch (260:7): [True: 1, False: 1.32k]
  ------------------
  261|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 11, 2}, "Kyber-768-90s-r3");
  262|      1|      case 0x6EF4D:
  ------------------
  |  Branch (262:7): [True: 1, False: 1.32k]
  ------------------
  263|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 11, 3}, "Kyber-1024-90s-r3");
  264|      1|      case 0x6F18E:
  ------------------
  |  Branch (264:7): [True: 1, False: 1.32k]
  ------------------
  265|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 14, 1}, "FrodoKEM-640-SHAKE");
  266|      1|      case 0x6F18F:
  ------------------
  |  Branch (266:7): [True: 1, False: 1.32k]
  ------------------
  267|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 14, 2}, "FrodoKEM-976-SHAKE");
  268|      1|      case 0x6F190:
  ------------------
  |  Branch (268:7): [True: 1, False: 1.32k]
  ------------------
  269|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 14, 3}, "FrodoKEM-1344-SHAKE");
  270|      1|      case 0x6F24F:
  ------------------
  |  Branch (270:7): [True: 1, False: 1.32k]
  ------------------
  271|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 15, 1}, "FrodoKEM-640-AES");
  272|      1|      case 0x6F250:
  ------------------
  |  Branch (272:7): [True: 1, False: 1.32k]
  ------------------
  273|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 15, 2}, "FrodoKEM-976-AES");
  274|      1|      case 0x6F251:
  ------------------
  |  Branch (274:7): [True: 1, False: 1.32k]
  ------------------
  275|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 15, 3}, "FrodoKEM-1344-AES");
  276|      1|      case 0x6F310:
  ------------------
  |  Branch (276:7): [True: 1, False: 1.32k]
  ------------------
  277|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 16, 1}, "eFrodoKEM-640-SHAKE");
  278|      1|      case 0x6F311:
  ------------------
  |  Branch (278:7): [True: 1, False: 1.32k]
  ------------------
  279|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 16, 2}, "eFrodoKEM-976-SHAKE");
  280|      1|      case 0x6F312:
  ------------------
  |  Branch (280:7): [True: 1, False: 1.32k]
  ------------------
  281|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 16, 3}, "eFrodoKEM-1344-SHAKE");
  282|      1|      case 0x6F3D1:
  ------------------
  |  Branch (282:7): [True: 1, False: 1.32k]
  ------------------
  283|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 17, 1}, "eFrodoKEM-640-AES");
  284|      1|      case 0x6F3D2:
  ------------------
  |  Branch (284:7): [True: 1, False: 1.32k]
  ------------------
  285|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 17, 2}, "eFrodoKEM-976-AES");
  286|      1|      case 0x6F3D3:
  ------------------
  |  Branch (286:7): [True: 1, False: 1.32k]
  ------------------
  287|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 17, 3}, "eFrodoKEM-1344-AES");
  288|      1|      case 0x6F492:
  ------------------
  |  Branch (288:7): [True: 1, False: 1.32k]
  ------------------
  289|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 18, 1}, "ClassicMcEliece_6688128pc");
  290|      1|      case 0x6F493:
  ------------------
  |  Branch (290:7): [True: 1, False: 1.32k]
  ------------------
  291|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 18, 2}, "ClassicMcEliece_6688128pcf");
  292|      1|      case 0x6F494:
  ------------------
  |  Branch (292:7): [True: 1, False: 1.32k]
  ------------------
  293|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 18, 3}, "ClassicMcEliece_6960119pc");
  294|      1|      case 0x6F495:
  ------------------
  |  Branch (294:7): [True: 1, False: 1.32k]
  ------------------
  295|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 18, 4}, "ClassicMcEliece_6960119pcf");
  296|      1|      case 0x6F496:
  ------------------
  |  Branch (296:7): [True: 1, False: 1.32k]
  ------------------
  297|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 18, 5}, "ClassicMcEliece_8192128pc");
  298|      1|      case 0x6F497:
  ------------------
  |  Branch (298:7): [True: 1, False: 1.32k]
  ------------------
  299|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 18, 6}, "ClassicMcEliece_8192128pcf");
  300|      1|      case 0x6F79D:
  ------------------
  |  Branch (300:7): [True: 1, False: 1.32k]
  ------------------
  301|      1|         return if_match(oid, {2, 16, 840, 1, 113730, 1, 13}, "Certificate Comment");
  302|      1|      case 0x701A0:
  ------------------
  |  Branch (302:7): [True: 1, False: 1.32k]
  ------------------
  303|      1|         return if_match(oid, {1, 3, 36, 3, 3, 2, 5, 2, 1}, "ECGDSA");
  304|      1|      case 0x70322:
  ------------------
  |  Branch (304:7): [True: 1, False: 1.32k]
  ------------------
  305|      1|         return if_match(oid, {1, 3, 36, 3, 3, 2, 5, 4, 1}, "ECGDSA/RIPEMD-160");
  306|      1|      case 0x70323:
  ------------------
  |  Branch (306:7): [True: 1, False: 1.32k]
  ------------------
  307|      1|         return if_match(oid, {1, 3, 36, 3, 3, 2, 5, 4, 2}, "ECGDSA/SHA-1");
  308|      1|      case 0x70324:
  ------------------
  |  Branch (308:7): [True: 1, False: 1.32k]
  ------------------
  309|      1|         return if_match(oid, {1, 3, 36, 3, 3, 2, 5, 4, 3}, "ECGDSA/SHA-224");
  310|      1|      case 0x70325:
  ------------------
  |  Branch (310:7): [True: 1, False: 1.32k]
  ------------------
  311|      1|         return if_match(oid, {1, 3, 36, 3, 3, 2, 5, 4, 4}, "ECGDSA/SHA-256");
  312|      1|      case 0x70326:
  ------------------
  |  Branch (312:7): [True: 1, False: 1.32k]
  ------------------
  313|      1|         return if_match(oid, {1, 3, 36, 3, 3, 2, 5, 4, 5}, "ECGDSA/SHA-384");
  314|      1|      case 0x70327:
  ------------------
  |  Branch (314:7): [True: 1, False: 1.32k]
  ------------------
  315|      1|         return if_match(oid, {1, 3, 36, 3, 3, 2, 5, 4, 6}, "ECGDSA/SHA-512");
  316|      1|      case 0x72B21:
  ------------------
  |  Branch (316:7): [True: 1, False: 1.32k]
  ------------------
  317|      1|         return if_match(oid, {1, 2, 643, 7, 1, 1, 1, 1}, "GOST-34.10-2012-256");
  318|      1|      case 0x72B22:
  ------------------
  |  Branch (318:7): [True: 1, False: 1.32k]
  ------------------
  319|      1|         return if_match(oid, {1, 2, 643, 7, 1, 1, 1, 2}, "GOST-34.10-2012-512");
  320|      1|      case 0x72BE3:
  ------------------
  |  Branch (320:7): [True: 1, False: 1.32k]
  ------------------
  321|      1|         return if_match(oid, {1, 2, 643, 7, 1, 1, 2, 2}, "Streebog-256");
  322|      1|      case 0x72BE4:
  ------------------
  |  Branch (322:7): [True: 1, False: 1.32k]
  ------------------
  323|      1|         return if_match(oid, {1, 2, 643, 7, 1, 1, 2, 3}, "Streebog-512");
  324|      1|      case 0x72CA4:
  ------------------
  |  Branch (324:7): [True: 1, False: 1.32k]
  ------------------
  325|      1|         return if_match(oid, {1, 2, 643, 7, 1, 1, 3, 2}, "GOST-34.10-2012-256/Streebog-256");
  326|      1|      case 0x72CA5:
  ------------------
  |  Branch (326:7): [True: 1, False: 1.32k]
  ------------------
  327|      1|         return if_match(oid, {1, 2, 643, 7, 1, 1, 3, 3}, "GOST-34.10-2012-512/Streebog-512");
  328|      1|      case 0x7C7C7:
  ------------------
  |  Branch (328:7): [True: 1, False: 1.32k]
  ------------------
  329|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 9, 22, 1}, "PKCS9.X509Certificate");
  330|      1|      case 0x7C7C8:
  ------------------
  |  Branch (330:7): [True: 1, False: 1.32k]
  ------------------
  331|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 9, 22, 2}, "PKCS9.SDSICertificate");
  332|      1|      case 0x7C888:
  ------------------
  |  Branch (332:7): [True: 1, False: 1.32k]
  ------------------
  333|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 9, 23, 1}, "PKCS9.X509CRL");
  334|      1|      case 0x7E10F:
  ------------------
  |  Branch (334:7): [True: 1, False: 1.32k]
  ------------------
  335|      1|         return if_match(oid, {2, 5, 4, 3}, "X520.CommonName");
  336|      1|      case 0x7E110:
  ------------------
  |  Branch (336:7): [True: 1, False: 1.32k]
  ------------------
  337|      1|         return if_match(oid, {2, 5, 4, 4}, "X520.Surname");
  338|      1|      case 0x7E111:
  ------------------
  |  Branch (338:7): [True: 1, False: 1.32k]
  ------------------
  339|      1|         return if_match(oid, {2, 5, 4, 5}, "X520.SerialNumber");
  340|      1|      case 0x7E112:
  ------------------
  |  Branch (340:7): [True: 1, False: 1.32k]
  ------------------
  341|      1|         return if_match(oid, {2, 5, 4, 6}, "X520.Country");
  342|      1|      case 0x7E113:
  ------------------
  |  Branch (342:7): [True: 1, False: 1.32k]
  ------------------
  343|      1|         return if_match(oid, {2, 5, 4, 7}, "X520.Locality");
  344|      1|      case 0x7E114:
  ------------------
  |  Branch (344:7): [True: 1, False: 1.32k]
  ------------------
  345|      1|         return if_match(oid, {2, 5, 4, 8}, "X520.State");
  346|      1|      case 0x7E115:
  ------------------
  |  Branch (346:7): [True: 1, False: 1.32k]
  ------------------
  347|      1|         return if_match(oid, {2, 5, 4, 9}, "X520.StreetAddress");
  348|      1|      case 0x7E116:
  ------------------
  |  Branch (348:7): [True: 1, False: 1.32k]
  ------------------
  349|      1|         return if_match(oid, {2, 5, 4, 10}, "X520.Organization");
  350|      1|      case 0x7E117:
  ------------------
  |  Branch (350:7): [True: 1, False: 1.32k]
  ------------------
  351|      1|         return if_match(oid, {2, 5, 4, 11}, "X520.OrganizationalUnit");
  352|      1|      case 0x7E118:
  ------------------
  |  Branch (352:7): [True: 1, False: 1.32k]
  ------------------
  353|      1|         return if_match(oid, {2, 5, 4, 12}, "X520.Title");
  354|      1|      case 0x7E136:
  ------------------
  |  Branch (354:7): [True: 1, False: 1.32k]
  ------------------
  355|      1|         return if_match(oid, {2, 5, 4, 42}, "X520.GivenName");
  356|      1|      case 0x7E137:
  ------------------
  |  Branch (356:7): [True: 1, False: 1.32k]
  ------------------
  357|      1|         return if_match(oid, {2, 5, 4, 43}, "X520.Initials");
  358|      1|      case 0x7E138:
  ------------------
  |  Branch (358:7): [True: 1, False: 1.32k]
  ------------------
  359|      1|         return if_match(oid, {2, 5, 4, 44}, "X520.GenerationalQualifier");
  360|      1|      case 0x7E13A:
  ------------------
  |  Branch (360:7): [True: 1, False: 1.32k]
  ------------------
  361|      1|         return if_match(oid, {2, 5, 4, 46}, "X520.DNQualifier");
  362|      1|      case 0x7E14D:
  ------------------
  |  Branch (362:7): [True: 1, False: 1.32k]
  ------------------
  363|      1|         return if_match(oid, {2, 5, 4, 65}, "X520.Pseudonym");
  364|      1|      case 0x7F3F3:
  ------------------
  |  Branch (364:7): [True: 1, False: 1.32k]
  ------------------
  365|      1|         return if_match(oid, {2, 5, 29, 14}, "X509v3.SubjectKeyIdentifier");
  366|      1|      case 0x7F3F4:
  ------------------
  |  Branch (366:7): [True: 1, False: 1.32k]
  ------------------
  367|      1|         return if_match(oid, {2, 5, 29, 15}, "X509v3.KeyUsage");
  368|      1|      case 0x7F3F5:
  ------------------
  |  Branch (368:7): [True: 1, False: 1.32k]
  ------------------
  369|      1|         return if_match(oid, {2, 5, 29, 16}, "X509v3.PrivateKeyUsagePeriod");
  370|      1|      case 0x7F3F6:
  ------------------
  |  Branch (370:7): [True: 1, False: 1.32k]
  ------------------
  371|      1|         return if_match(oid, {2, 5, 29, 17}, "X509v3.SubjectAlternativeName");
  372|      1|      case 0x7F3F7:
  ------------------
  |  Branch (372:7): [True: 1, False: 1.32k]
  ------------------
  373|      1|         return if_match(oid, {2, 5, 29, 18}, "X509v3.IssuerAlternativeName");
  374|      1|      case 0x7F3F8:
  ------------------
  |  Branch (374:7): [True: 1, False: 1.32k]
  ------------------
  375|      1|         return if_match(oid, {2, 5, 29, 19}, "X509v3.BasicConstraints");
  376|      1|      case 0x7F3F9:
  ------------------
  |  Branch (376:7): [True: 1, False: 1.32k]
  ------------------
  377|      1|         return if_match(oid, {2, 5, 29, 20}, "X509v3.CRLNumber");
  378|      1|      case 0x7F3FA:
  ------------------
  |  Branch (378:7): [True: 1, False: 1.32k]
  ------------------
  379|      1|         return if_match(oid, {2, 5, 29, 21}, "X509v3.ReasonCode");
  380|      1|      case 0x7F3FC:
  ------------------
  |  Branch (380:7): [True: 1, False: 1.32k]
  ------------------
  381|      1|         return if_match(oid, {2, 5, 29, 23}, "X509v3.HoldInstructionCode");
  382|      1|      case 0x7F3FD:
  ------------------
  |  Branch (382:7): [True: 1, False: 1.32k]
  ------------------
  383|      1|         return if_match(oid, {2, 5, 29, 24}, "X509v3.InvalidityDate");
  384|      1|      case 0x7F401:
  ------------------
  |  Branch (384:7): [True: 1, False: 1.32k]
  ------------------
  385|      1|         return if_match(oid, {2, 5, 29, 28}, "X509v3.CRLIssuingDistributionPoint");
  386|      1|      case 0x7F403:
  ------------------
  |  Branch (386:7): [True: 1, False: 1.32k]
  ------------------
  387|      1|         return if_match(oid, {2, 5, 29, 30}, "X509v3.NameConstraints");
  388|      1|      case 0x7F404:
  ------------------
  |  Branch (388:7): [True: 1, False: 1.32k]
  ------------------
  389|      1|         return if_match(oid, {2, 5, 29, 31}, "X509v3.CRLDistributionPoints");
  390|      1|      case 0x7F405:
  ------------------
  |  Branch (390:7): [True: 1, False: 1.32k]
  ------------------
  391|      1|         return if_match(oid, {2, 5, 29, 32}, "X509v3.CertificatePolicies");
  392|      1|      case 0x7F408:
  ------------------
  |  Branch (392:7): [True: 1, False: 1.32k]
  ------------------
  393|      1|         return if_match(oid, {2, 5, 29, 35}, "X509v3.AuthorityKeyIdentifier");
  394|      1|      case 0x7F409:
  ------------------
  |  Branch (394:7): [True: 1, False: 1.32k]
  ------------------
  395|      1|         return if_match(oid, {2, 5, 29, 36}, "X509v3.PolicyConstraints");
  396|      1|      case 0x7F40A:
  ------------------
  |  Branch (396:7): [True: 1, False: 1.32k]
  ------------------
  397|      1|         return if_match(oid, {2, 5, 29, 37}, "X509v3.ExtendedKeyUsage");
  398|      1|      case 0x7F41D:
  ------------------
  |  Branch (398:7): [True: 1, False: 1.32k]
  ------------------
  399|      1|         return if_match(oid, {2, 5, 29, 56}, "X509v3.NoRevocationAvailable");
  400|      1|      case 0x80B84:
  ------------------
  |  Branch (400:7): [True: 1, False: 1.32k]
  ------------------
  401|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 2, 1}, "AES-128/OCB");
  402|      1|      case 0x80B85:
  ------------------
  |  Branch (402:7): [True: 1, False: 1.32k]
  ------------------
  403|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 2, 2}, "AES-192/OCB");
  404|      1|      case 0x80B86:
  ------------------
  |  Branch (404:7): [True: 1, False: 1.32k]
  ------------------
  405|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 2, 3}, "AES-256/OCB");
  406|      1|      case 0x80B87:
  ------------------
  |  Branch (406:7): [True: 1, False: 1.32k]
  ------------------
  407|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 2, 4}, "Serpent/OCB");
  408|      1|      case 0x80B88:
  ------------------
  |  Branch (408:7): [True: 1, False: 1.32k]
  ------------------
  409|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 2, 5}, "Twofish/OCB");
  410|      1|      case 0x80B89:
  ------------------
  |  Branch (410:7): [True: 1, False: 1.32k]
  ------------------
  411|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 2, 6}, "Camellia-128/OCB");
  412|      1|      case 0x80B8A:
  ------------------
  |  Branch (412:7): [True: 1, False: 1.32k]
  ------------------
  413|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 2, 7}, "Camellia-192/OCB");
  414|      1|      case 0x80B8B:
  ------------------
  |  Branch (414:7): [True: 1, False: 1.32k]
  ------------------
  415|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 2, 8}, "Camellia-256/OCB");
  416|      1|      case 0x80D06:
  ------------------
  |  Branch (416:7): [True: 1, False: 1.32k]
  ------------------
  417|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 4, 1}, "AES-128/SIV");
  418|      1|      case 0x80D07:
  ------------------
  |  Branch (418:7): [True: 1, False: 1.32k]
  ------------------
  419|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 4, 2}, "AES-192/SIV");
  420|      1|      case 0x80D08:
  ------------------
  |  Branch (420:7): [True: 1, False: 1.32k]
  ------------------
  421|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 4, 3}, "AES-256/SIV");
  422|      1|      case 0x80D09:
  ------------------
  |  Branch (422:7): [True: 1, False: 1.32k]
  ------------------
  423|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 4, 4}, "Serpent/SIV");
  424|      1|      case 0x80D0A:
  ------------------
  |  Branch (424:7): [True: 1, False: 1.32k]
  ------------------
  425|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 4, 5}, "Twofish/SIV");
  426|      1|      case 0x80D0B:
  ------------------
  |  Branch (426:7): [True: 1, False: 1.32k]
  ------------------
  427|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 4, 6}, "Camellia-128/SIV");
  428|      1|      case 0x80D0C:
  ------------------
  |  Branch (428:7): [True: 1, False: 1.32k]
  ------------------
  429|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 4, 7}, "Camellia-192/SIV");
  430|      1|      case 0x80D0D:
  ------------------
  |  Branch (430:7): [True: 1, False: 1.32k]
  ------------------
  431|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 4, 8}, "Camellia-256/SIV");
  432|      1|      case 0x80D0E:
  ------------------
  |  Branch (432:7): [True: 1, False: 1.32k]
  ------------------
  433|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 4, 9}, "SM4/SIV");
  434|      1|      case 0x84C6A:
  ------------------
  |  Branch (434:7): [True: 1, False: 1.32k]
  ------------------
  435|      1|         return if_match(oid, {1, 2, 392, 200011, 61, 1, 1, 1, 2}, "Camellia-128/CBC");
  436|      1|      case 0x84C6B:
  ------------------
  |  Branch (436:7): [True: 1, False: 1.32k]
  ------------------
  437|      1|         return if_match(oid, {1, 2, 392, 200011, 61, 1, 1, 1, 3}, "Camellia-192/CBC");
  438|      1|      case 0x84C6C:
  ------------------
  |  Branch (438:7): [True: 1, False: 1.32k]
  ------------------
  439|      1|         return if_match(oid, {1, 2, 392, 200011, 61, 1, 1, 1, 4}, "Camellia-256/CBC");
  440|      1|      case 0x88CD3:
  ------------------
  |  Branch (440:7): [True: 1, False: 1.32k]
  ------------------
  441|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 9, 16, 3, 6}, "KeyWrap.TripleDES");
  442|      1|      case 0x88CD5:
  ------------------
  |  Branch (442:7): [True: 1, False: 1.32k]
  ------------------
  443|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 9, 16, 3, 8}, "Compression.Zlib");
  444|      1|      case 0x88CDE:
  ------------------
  |  Branch (444:7): [True: 1, False: 1.32k]
  ------------------
  445|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 9, 16, 3, 17}, "HSS-LMS");
  446|      1|      case 0x88CDF:
  ------------------
  |  Branch (446:7): [True: 1, False: 1.32k]
  ------------------
  447|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 9, 16, 3, 18}, "ChaCha20Poly1305");
  448|      1|      case 0x92296:
  ------------------
  |  Branch (448:7): [True: 1, False: 1.32k]
  ------------------
  449|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 1, 2}, "AES-128/CBC");
  450|      1|      case 0x92299:
  ------------------
  |  Branch (450:7): [True: 1, False: 1.32k]
  ------------------
  451|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 1, 5}, "KeyWrap.AES-128");
  452|      1|      case 0x9229A:
  ------------------
  |  Branch (452:7): [True: 1, False: 1.32k]
  ------------------
  453|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 1, 6}, "AES-128/GCM");
  454|      1|      case 0x9229B:
  ------------------
  |  Branch (454:7): [True: 1, False: 1.32k]
  ------------------
  455|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 1, 7}, "AES-128/CCM");
  456|      1|      case 0x922AA:
  ------------------
  |  Branch (456:7): [True: 1, False: 1.32k]
  ------------------
  457|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 1, 22}, "AES-192/CBC");
  458|      1|      case 0x922AD:
  ------------------
  |  Branch (458:7): [True: 1, False: 1.32k]
  ------------------
  459|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 1, 25}, "KeyWrap.AES-192");
  460|      1|      case 0x922AE:
  ------------------
  |  Branch (460:7): [True: 1, False: 1.32k]
  ------------------
  461|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 1, 26}, "AES-192/GCM");
  462|      1|      case 0x922AF:
  ------------------
  |  Branch (462:7): [True: 1, False: 1.32k]
  ------------------
  463|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 1, 27}, "AES-192/CCM");
  464|      1|      case 0x922BE:
  ------------------
  |  Branch (464:7): [True: 1, False: 1.32k]
  ------------------
  465|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 1, 42}, "AES-256/CBC");
  466|      1|      case 0x922C1:
  ------------------
  |  Branch (466:7): [True: 1, False: 1.32k]
  ------------------
  467|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 1, 45}, "KeyWrap.AES-256");
  468|      1|      case 0x922C2:
  ------------------
  |  Branch (468:7): [True: 1, False: 1.32k]
  ------------------
  469|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 1, 46}, "AES-256/GCM");
  470|      1|      case 0x922C3:
  ------------------
  |  Branch (470:7): [True: 1, False: 1.32k]
  ------------------
  471|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 1, 47}, "AES-256/CCM");
  472|      1|      case 0x92356:
  ------------------
  |  Branch (472:7): [True: 1, False: 1.32k]
  ------------------
  473|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 2, 1}, "SHA-256");
  474|      1|      case 0x92357:
  ------------------
  |  Branch (474:7): [True: 1, False: 1.32k]
  ------------------
  475|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 2, 2}, "SHA-384");
  476|      1|      case 0x92358:
  ------------------
  |  Branch (476:7): [True: 1, False: 1.32k]
  ------------------
  477|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 2, 3}, "SHA-512");
  478|      1|      case 0x92359:
  ------------------
  |  Branch (478:7): [True: 1, False: 1.32k]
  ------------------
  479|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 2, 4}, "SHA-224");
  480|      1|      case 0x9235B:
  ------------------
  |  Branch (480:7): [True: 1, False: 1.32k]
  ------------------
  481|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 2, 6}, "SHA-512-256");
  482|      1|      case 0x9235C:
  ------------------
  |  Branch (482:7): [True: 1, False: 1.32k]
  ------------------
  483|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 2, 7}, "SHA-3(224)");
  484|      1|      case 0x9235D:
  ------------------
  |  Branch (484:7): [True: 1, False: 1.32k]
  ------------------
  485|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 2, 8}, "SHA-3(256)");
  486|      1|      case 0x9235E:
  ------------------
  |  Branch (486:7): [True: 1, False: 1.32k]
  ------------------
  487|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 2, 9}, "SHA-3(384)");
  488|      1|      case 0x9235F:
  ------------------
  |  Branch (488:7): [True: 1, False: 1.32k]
  ------------------
  489|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 2, 10}, "SHA-3(512)");
  490|      1|      case 0x92360:
  ------------------
  |  Branch (490:7): [True: 1, False: 1.32k]
  ------------------
  491|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 2, 11}, "SHAKE-128");
  492|      1|      case 0x92361:
  ------------------
  |  Branch (492:7): [True: 1, False: 1.32k]
  ------------------
  493|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 2, 12}, "SHAKE-256");
  494|      1|      case 0x92417:
  ------------------
  |  Branch (494:7): [True: 1, False: 1.32k]
  ------------------
  495|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 1}, "DSA/SHA-224");
  496|      1|      case 0x92418:
  ------------------
  |  Branch (496:7): [True: 1, False: 1.32k]
  ------------------
  497|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 2}, "DSA/SHA-256");
  498|      1|      case 0x92419:
  ------------------
  |  Branch (498:7): [True: 1, False: 1.32k]
  ------------------
  499|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 3}, "DSA/SHA-384");
  500|      1|      case 0x9241A:
  ------------------
  |  Branch (500:7): [True: 1, False: 1.32k]
  ------------------
  501|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 4}, "DSA/SHA-512");
  502|      1|      case 0x9241B:
  ------------------
  |  Branch (502:7): [True: 1, False: 1.32k]
  ------------------
  503|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 5}, "DSA/SHA-3(224)");
  504|      1|      case 0x9241C:
  ------------------
  |  Branch (504:7): [True: 1, False: 1.32k]
  ------------------
  505|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 6}, "DSA/SHA-3(256)");
  506|      1|      case 0x9241D:
  ------------------
  |  Branch (506:7): [True: 1, False: 1.32k]
  ------------------
  507|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 7}, "DSA/SHA-3(384)");
  508|      1|      case 0x9241E:
  ------------------
  |  Branch (508:7): [True: 1, False: 1.32k]
  ------------------
  509|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 8}, "DSA/SHA-3(512)");
  510|      1|      case 0x9241F:
  ------------------
  |  Branch (510:7): [True: 1, False: 1.32k]
  ------------------
  511|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 9}, "ECDSA/SHA-3(224)");
  512|      1|      case 0x92420:
  ------------------
  |  Branch (512:7): [True: 1, False: 1.32k]
  ------------------
  513|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 10}, "ECDSA/SHA-3(256)");
  514|      1|      case 0x92421:
  ------------------
  |  Branch (514:7): [True: 1, False: 1.32k]
  ------------------
  515|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 11}, "ECDSA/SHA-3(384)");
  516|      1|      case 0x92422:
  ------------------
  |  Branch (516:7): [True: 1, False: 1.32k]
  ------------------
  517|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 12}, "ECDSA/SHA-3(512)");
  518|      1|      case 0x92423:
  ------------------
  |  Branch (518:7): [True: 1, False: 1.32k]
  ------------------
  519|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 13}, "RSA/PKCS1v15(SHA-3(224))");
  520|      1|      case 0x92424:
  ------------------
  |  Branch (520:7): [True: 1, False: 1.32k]
  ------------------
  521|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 14}, "RSA/PKCS1v15(SHA-3(256))");
  522|      1|      case 0x92425:
  ------------------
  |  Branch (522:7): [True: 1, False: 1.32k]
  ------------------
  523|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 15}, "RSA/PKCS1v15(SHA-3(384))");
  524|      1|      case 0x92426:
  ------------------
  |  Branch (524:7): [True: 1, False: 1.32k]
  ------------------
  525|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 16}, "RSA/PKCS1v15(SHA-3(512))");
  526|      1|      case 0x92427:
  ------------------
  |  Branch (526:7): [True: 1, False: 1.32k]
  ------------------
  527|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 17}, "ML-DSA-4x4");
  528|      1|      case 0x92428:
  ------------------
  |  Branch (528:7): [True: 1, False: 1.32k]
  ------------------
  529|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 18}, "ML-DSA-6x5");
  530|      1|      case 0x92429:
  ------------------
  |  Branch (530:7): [True: 1, False: 1.32k]
  ------------------
  531|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 19}, "ML-DSA-8x7");
  532|      1|      case 0x9242A:
  ------------------
  |  Branch (532:7): [True: 1, False: 1.32k]
  ------------------
  533|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 20}, "SLH-DSA-SHA2-128s");
  534|      1|      case 0x9242B:
  ------------------
  |  Branch (534:7): [True: 1, False: 1.32k]
  ------------------
  535|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 21}, "SLH-DSA-SHA2-128f");
  536|      1|      case 0x9242C:
  ------------------
  |  Branch (536:7): [True: 1, False: 1.32k]
  ------------------
  537|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 22}, "SLH-DSA-SHA2-192s");
  538|      1|      case 0x9242D:
  ------------------
  |  Branch (538:7): [True: 1, False: 1.32k]
  ------------------
  539|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 23}, "SLH-DSA-SHA2-192f");
  540|      1|      case 0x9242E:
  ------------------
  |  Branch (540:7): [True: 1, False: 1.32k]
  ------------------
  541|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 24}, "SLH-DSA-SHA2-256s");
  542|      1|      case 0x9242F:
  ------------------
  |  Branch (542:7): [True: 1, False: 1.32k]
  ------------------
  543|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 25}, "SLH-DSA-SHA2-256f");
  544|      1|      case 0x92430:
  ------------------
  |  Branch (544:7): [True: 1, False: 1.32k]
  ------------------
  545|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 26}, "SLH-DSA-SHAKE-128s");
  546|      1|      case 0x92431:
  ------------------
  |  Branch (546:7): [True: 1, False: 1.32k]
  ------------------
  547|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 27}, "SLH-DSA-SHAKE-128f");
  548|      1|      case 0x92432:
  ------------------
  |  Branch (548:7): [True: 1, False: 1.32k]
  ------------------
  549|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 28}, "SLH-DSA-SHAKE-192s");
  550|      1|      case 0x92433:
  ------------------
  |  Branch (550:7): [True: 1, False: 1.32k]
  ------------------
  551|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 29}, "SLH-DSA-SHAKE-192f");
  552|      1|      case 0x92434:
  ------------------
  |  Branch (552:7): [True: 1, False: 1.32k]
  ------------------
  553|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 30}, "SLH-DSA-SHAKE-256s");
  554|      1|      case 0x92435:
  ------------------
  |  Branch (554:7): [True: 1, False: 1.32k]
  ------------------
  555|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 3, 31}, "SLH-DSA-SHAKE-256f");
  556|      1|      case 0x924D8:
  ------------------
  |  Branch (556:7): [True: 1, False: 1.32k]
  ------------------
  557|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 4, 1}, "ML-KEM-512");
  558|      1|      case 0x924D9:
  ------------------
  |  Branch (558:7): [True: 1, False: 1.32k]
  ------------------
  559|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 4, 2}, "ML-KEM-768");
  560|      1|      case 0x924DA:
  ------------------
  |  Branch (560:7): [True: 1, False: 1.32k]
  ------------------
  561|      1|         return if_match(oid, {2, 16, 840, 1, 101, 3, 4, 4, 3}, "ML-KEM-1024");
  562|      1|      case 0x9479F:
  ------------------
  |  Branch (562:7): [True: 1, False: 1.32k]
  ------------------
  563|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 1, 1}, "PKIX.AuthorityInformationAccess");
  564|      1|      case 0x947A5:
  ------------------
  |  Branch (564:7): [True: 1, False: 1.32k]
  ------------------
  565|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 1, 7}, "PKIX.IpAddrBlocks");
  566|      1|      case 0x947A6:
  ------------------
  |  Branch (566:7): [True: 1, False: 1.32k]
  ------------------
  567|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 1, 8}, "PKIX.AutonomousSysIds");
  568|      1|      case 0x947B8:
  ------------------
  |  Branch (568:7): [True: 1, False: 1.32k]
  ------------------
  569|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 1, 26}, "PKIX.TNAuthList");
  570|      1|      case 0x94921:
  ------------------
  |  Branch (570:7): [True: 1, False: 1.32k]
  ------------------
  571|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 3, 1}, "PKIX.ServerAuth");
  572|      1|      case 0x94922:
  ------------------
  |  Branch (572:7): [True: 1, False: 1.32k]
  ------------------
  573|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 3, 2}, "PKIX.ClientAuth");
  574|      1|      case 0x94923:
  ------------------
  |  Branch (574:7): [True: 1, False: 1.32k]
  ------------------
  575|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 3, 3}, "PKIX.CodeSigning");
  576|      1|      case 0x94924:
  ------------------
  |  Branch (576:7): [True: 1, False: 1.32k]
  ------------------
  577|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 3, 4}, "PKIX.EmailProtection");
  578|      1|      case 0x94925:
  ------------------
  |  Branch (578:7): [True: 1, False: 1.32k]
  ------------------
  579|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 3, 5}, "PKIX.IPsecEndSystem");
  580|      1|      case 0x94926:
  ------------------
  |  Branch (580:7): [True: 1, False: 1.32k]
  ------------------
  581|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 3, 6}, "PKIX.IPsecTunnel");
  582|      1|      case 0x94927:
  ------------------
  |  Branch (582:7): [True: 1, False: 1.32k]
  ------------------
  583|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 3, 7}, "PKIX.IPsecUser");
  584|      1|      case 0x94928:
  ------------------
  |  Branch (584:7): [True: 1, False: 1.32k]
  ------------------
  585|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 3, 8}, "PKIX.TimeStamping");
  586|      1|      case 0x94929:
  ------------------
  |  Branch (586:7): [True: 1, False: 1.32k]
  ------------------
  587|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 3, 9}, "PKIX.OCSPSigning");
  588|      1|      case 0x94CEA:
  ------------------
  |  Branch (588:7): [True: 1, False: 1.32k]
  ------------------
  589|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 8, 5}, "PKIX.XMPPAddr");
  590|      1|      case 0x94CEE:
  ------------------
  |  Branch (590:7): [True: 1, False: 1.32k]
  ------------------
  591|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 8, 9}, "PKIX.SmtpUTF8Mailbox");
  592|      1|      case 0x954DB:
  ------------------
  |  Branch (592:7): [True: 1, False: 1.32k]
  ------------------
  593|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 311, 20, 2, 2}, "Microsoft SmartcardLogon");
  594|      1|      case 0x954DC:
  ------------------
  |  Branch (594:7): [True: 1, False: 1.32k]
  ------------------
  595|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 311, 20, 2, 3}, "Microsoft UPN");
  596|      1|      case 0x96B0E:
  ------------------
  |  Branch (596:7): [True: 1, False: 1.32k]
  ------------------
  597|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 48, 1}, "PKIX.OCSP");
  598|      1|      case 0x96B0F:
  ------------------
  |  Branch (598:7): [True: 1, False: 1.32k]
  ------------------
  599|      1|         return if_match(oid, {1, 3, 6, 1, 5, 5, 7, 48, 2}, "PKIX.CertificateAuthorityIssuers");
  600|      1|      case 0x96C77:
  ------------------
  |  Branch (600:7): [True: 1, False: 1.32k]
  ------------------
  601|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 12, 1, 3}, "PBE-SHA1-3DES");
  602|      1|      case 0x96C78:
  ------------------
  |  Branch (602:7): [True: 1, False: 1.32k]
  ------------------
  603|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 12, 1, 4}, "PBE-SHA1-2DES");
  604|      1|      case 0x9A008:
  ------------------
  |  Branch (604:7): [True: 1, False: 1.32k]
  ------------------
  605|      1|         return if_match(oid, {1, 3, 36, 3, 3, 2, 8, 1, 1, 1}, "brainpool160r1");
  606|      1|      case 0x9A00A:
  ------------------
  |  Branch (606:7): [True: 1, False: 1.32k]
  ------------------
  607|      1|         return if_match(oid, {1, 3, 36, 3, 3, 2, 8, 1, 1, 3}, "brainpool192r1");
  608|      1|      case 0x9A00C:
  ------------------
  |  Branch (608:7): [True: 1, False: 1.32k]
  ------------------
  609|      1|         return if_match(oid, {1, 3, 36, 3, 3, 2, 8, 1, 1, 5}, "brainpool224r1");
  610|      1|      case 0x9A00E:
  ------------------
  |  Branch (610:7): [True: 1, False: 1.32k]
  ------------------
  611|      1|         return if_match(oid, {1, 3, 36, 3, 3, 2, 8, 1, 1, 7}, "brainpool256r1");
  612|      1|      case 0x9A010:
  ------------------
  |  Branch (612:7): [True: 1, False: 1.32k]
  ------------------
  613|      1|         return if_match(oid, {1, 3, 36, 3, 3, 2, 8, 1, 1, 9}, "brainpool320r1");
  614|      1|      case 0x9A012:
  ------------------
  |  Branch (614:7): [True: 1, False: 1.32k]
  ------------------
  615|      1|         return if_match(oid, {1, 3, 36, 3, 3, 2, 8, 1, 1, 11}, "brainpool384r1");
  616|      1|      case 0x9A014:
  ------------------
  |  Branch (616:7): [True: 1, False: 1.32k]
  ------------------
  617|      1|         return if_match(oid, {1, 3, 36, 3, 3, 2, 8, 1, 1, 13}, "brainpool512r1");
  618|      1|      case 0xA0D61:
  ------------------
  |  Branch (618:7): [True: 1, False: 1.32k]
  ------------------
  619|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 3}, "McEliece");
  620|      1|      case 0xA0D63:
  ------------------
  |  Branch (620:7): [True: 1, False: 1.32k]
  ------------------
  621|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 5}, "XMSS-draft6");
  622|      1|      case 0xA0D66:
  ------------------
  |  Branch (622:7): [True: 1, False: 1.32k]
  ------------------
  623|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 8}, "XMSS-draft12");
  624|      1|      case 0xA0D6B:
  ------------------
  |  Branch (624:7): [True: 1, False: 1.32k]
  ------------------
  625|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 13}, "HSS-LMS-Private-Key");
  626|      1|      case 0xA0EE1:
  ------------------
  |  Branch (626:7): [True: 1, False: 1.32k]
  ------------------
  627|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 1}, "Serpent/CBC");
  628|      1|      case 0xA0EE2:
  ------------------
  |  Branch (628:7): [True: 1, False: 1.32k]
  ------------------
  629|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 2}, "Threefish-512/CBC");
  630|      1|      case 0xA0EE3:
  ------------------
  |  Branch (630:7): [True: 1, False: 1.32k]
  ------------------
  631|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 3}, "Twofish/CBC");
  632|      1|      case 0xA0F45:
  ------------------
  |  Branch (632:7): [True: 1, False: 1.32k]
  ------------------
  633|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 101}, "Serpent/GCM");
  634|      1|      case 0xA0F46:
  ------------------
  |  Branch (634:7): [True: 1, False: 1.32k]
  ------------------
  635|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 3, 102}, "Twofish/GCM");
  636|      1|      case 0xA0FA2:
  ------------------
  |  Branch (636:7): [True: 1, False: 1.32k]
  ------------------
  637|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 4, 1}, "numsp256d1");
  638|      1|      case 0xA0FA3:
  ------------------
  |  Branch (638:7): [True: 1, False: 1.32k]
  ------------------
  639|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 4, 2}, "numsp384d1");
  640|      1|      case 0xA0FA4:
  ------------------
  |  Branch (640:7): [True: 1, False: 1.32k]
  ------------------
  641|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 4, 3}, "numsp512d1");
  642|      1|      case 0xA244B:
  ------------------
  |  Branch (642:7): [True: 1, False: 1.32k]
  ------------------
  643|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 22554, 5, 1, 1}, "ClassicMcEliece_348864");
  644|      1|      case 0xA244C:
  ------------------
  |  Branch (644:7): [True: 1, False: 1.32k]
  ------------------
  645|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 22554, 5, 1, 2}, "ClassicMcEliece_348864f");
  646|      1|      case 0xA244D:
  ------------------
  |  Branch (646:7): [True: 1, False: 1.32k]
  ------------------
  647|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 22554, 5, 1, 3}, "ClassicMcEliece_460896");
  648|      1|      case 0xA244E:
  ------------------
  |  Branch (648:7): [True: 1, False: 1.32k]
  ------------------
  649|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 22554, 5, 1, 4}, "ClassicMcEliece_460896f");
  650|      1|      case 0xA244F:
  ------------------
  |  Branch (650:7): [True: 1, False: 1.32k]
  ------------------
  651|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 22554, 5, 1, 5}, "ClassicMcEliece_6688128");
  652|      1|      case 0xA2450:
  ------------------
  |  Branch (652:7): [True: 1, False: 1.32k]
  ------------------
  653|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 22554, 5, 1, 6}, "ClassicMcEliece_6688128f");
  654|      1|      case 0xA2451:
  ------------------
  |  Branch (654:7): [True: 1, False: 1.32k]
  ------------------
  655|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 22554, 5, 1, 7}, "ClassicMcEliece_6960119");
  656|      1|      case 0xA2452:
  ------------------
  |  Branch (656:7): [True: 1, False: 1.32k]
  ------------------
  657|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 22554, 5, 1, 8}, "ClassicMcEliece_6960119f");
  658|      1|      case 0xA2453:
  ------------------
  |  Branch (658:7): [True: 1, False: 1.32k]
  ------------------
  659|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 22554, 5, 1, 9}, "ClassicMcEliece_8192128");
  660|      1|      case 0xA2454:
  ------------------
  |  Branch (660:7): [True: 1, False: 1.32k]
  ------------------
  661|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 22554, 5, 1, 10}, "ClassicMcEliece_8192128f");
  662|      1|      case 0xAF989:
  ------------------
  |  Branch (662:7): [True: 1, False: 1.32k]
  ------------------
  663|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 1, 1}, "RSA");
  664|      1|      case 0xAF98A:
  ------------------
  |  Branch (664:7): [True: 1, False: 1.32k]
  ------------------
  665|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 1, 2}, "RSA/PKCS1v15(MD2)");
  666|      1|      case 0xAF98C:
  ------------------
  |  Branch (666:7): [True: 1, False: 1.32k]
  ------------------
  667|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 1, 4}, "RSA/PKCS1v15(MD5)");
  668|      1|      case 0xAF98D:
  ------------------
  |  Branch (668:7): [True: 1, False: 1.32k]
  ------------------
  669|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 1, 5}, "RSA/PKCS1v15(SHA-1)");
  670|      1|      case 0xAF98F:
  ------------------
  |  Branch (670:7): [True: 1, False: 1.32k]
  ------------------
  671|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 1, 7}, "RSA/OAEP");
  672|      1|      case 0xAF990:
  ------------------
  |  Branch (672:7): [True: 1, False: 1.32k]
  ------------------
  673|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 1, 8}, "MGF1");
  674|      1|      case 0xAF992:
  ------------------
  |  Branch (674:7): [True: 1, False: 1.32k]
  ------------------
  675|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 1, 10}, "RSA/PSS");
  676|      1|      case 0xAF993:
  ------------------
  |  Branch (676:7): [True: 1, False: 1.32k]
  ------------------
  677|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 1, 11}, "RSA/PKCS1v15(SHA-256)");
  678|      1|      case 0xAF994:
  ------------------
  |  Branch (678:7): [True: 1, False: 1.32k]
  ------------------
  679|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 1, 12}, "RSA/PKCS1v15(SHA-384)");
  680|      1|      case 0xAF995:
  ------------------
  |  Branch (680:7): [True: 1, False: 1.32k]
  ------------------
  681|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 1, 13}, "RSA/PKCS1v15(SHA-512)");
  682|      1|      case 0xAF996:
  ------------------
  |  Branch (682:7): [True: 1, False: 1.32k]
  ------------------
  683|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 1, 14}, "RSA/PKCS1v15(SHA-224)");
  684|      1|      case 0xAF998:
  ------------------
  |  Branch (684:7): [True: 1, False: 1.32k]
  ------------------
  685|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 1, 16}, "RSA/PKCS1v15(SHA-512-256)");
  686|      1|      case 0xAFC98:
  ------------------
  |  Branch (686:7): [True: 1, False: 1.32k]
  ------------------
  687|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 5, 12}, "PKCS5.PBKDF2");
  688|      1|      case 0xAFC99:
  ------------------
  |  Branch (688:7): [True: 1, False: 1.32k]
  ------------------
  689|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 5, 13}, "PBE-PKCS5v20");
  690|      1|      case 0xAFE0F:
  ------------------
  |  Branch (690:7): [True: 1, False: 1.32k]
  ------------------
  691|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 7, 1}, "PKCS7.Data");
  692|      1|      case 0xAFE14:
  ------------------
  |  Branch (692:7): [True: 1, False: 1.32k]
  ------------------
  693|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 7, 6}, "PKCS7.EncryptedData");
  694|      1|      case 0xAFF91:
  ------------------
  |  Branch (694:7): [True: 1, False: 1.32k]
  ------------------
  695|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 9, 1}, "PKCS9.EmailAddress");
  696|      1|      case 0xAFF92:
  ------------------
  |  Branch (696:7): [True: 1, False: 1.32k]
  ------------------
  697|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 9, 2}, "PKCS9.UnstructuredName");
  698|      1|      case 0xAFF93:
  ------------------
  |  Branch (698:7): [True: 1, False: 1.32k]
  ------------------
  699|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 9, 3}, "PKCS9.ContentType");
  700|      1|      case 0xAFF94:
  ------------------
  |  Branch (700:7): [True: 1, False: 1.32k]
  ------------------
  701|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 9, 4}, "PKCS9.MessageDigest");
  702|      1|      case 0xAFF97:
  ------------------
  |  Branch (702:7): [True: 1, False: 1.32k]
  ------------------
  703|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 9, 7}, "PKCS9.ChallengePassword");
  704|      1|      case 0xAFF9E:
  ------------------
  |  Branch (704:7): [True: 1, False: 1.32k]
  ------------------
  705|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 9, 14}, "PKCS9.ExtensionRequest");
  706|      1|      case 0xAFFA4:
  ------------------
  |  Branch (706:7): [True: 1, False: 1.32k]
  ------------------
  707|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 9, 20}, "PKCS9.FriendlyName");
  708|      1|      case 0xAFFA5:
  ------------------
  |  Branch (708:7): [True: 1, False: 1.32k]
  ------------------
  709|      1|         return if_match(oid, {1, 2, 840, 113549, 1, 9, 21}, "PKCS9.LocalKeyId");
  710|      1|      case 0xC0226:
  ------------------
  |  Branch (710:7): [True: 1, False: 1.32k]
  ------------------
  711|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 11591, 4, 11}, "Scrypt");
  712|      1|      case 0xC0A67:
  ------------------
  |  Branch (712:7): [True: 1, False: 1.32k]
  ------------------
  713|      1|         return if_match(oid, {1, 3, 6, 1, 4, 1, 11591, 15, 1}, "OpenPGP.Ed25519");
  714|      1|      case 0xC4CE5:
  ------------------
  |  Branch (714:7): [True: 1, False: 1.32k]
  ------------------
  715|      1|         return if_match(oid, {1, 2, 643, 100, 1}, "GOST.OGRN");
  716|      1|      case 0xC4D53:
  ------------------
  |  Branch (716:7): [True: 1, False: 1.32k]
  ------------------
  717|      1|         return if_match(oid, {1, 2, 643, 100, 111}, "GOST.SubjectSigningTool");
  718|      1|      case 0xC4D54:
  ------------------
  |  Branch (718:7): [True: 1, False: 1.32k]
  ------------------
  719|      1|         return if_match(oid, {1, 2, 643, 100, 112}, "GOST.IssuerSigningTool");
  720|      1|      case 0xC9C50:
  ------------------
  |  Branch (720:7): [True: 1, False: 1.32k]
  ------------------
  721|      1|         return if_match(oid, {1, 2, 840, 10045, 3, 1, 1}, "secp192r1");
  722|      1|      case 0xC9C51:
  ------------------
  |  Branch (722:7): [True: 1, False: 1.32k]
  ------------------
  723|      1|         return if_match(oid, {1, 2, 840, 10045, 3, 1, 2}, "x962_p192v2");
  724|      1|      case 0xC9C52:
  ------------------
  |  Branch (724:7): [True: 1, False: 1.32k]
  ------------------
  725|      1|         return if_match(oid, {1, 2, 840, 10045, 3, 1, 3}, "x962_p192v3");
  726|      1|      case 0xC9C53:
  ------------------
  |  Branch (726:7): [True: 1, False: 1.32k]
  ------------------
  727|      1|         return if_match(oid, {1, 2, 840, 10045, 3, 1, 4}, "x962_p239v1");
  728|      1|      case 0xC9C54:
  ------------------
  |  Branch (728:7): [True: 1, False: 1.32k]
  ------------------
  729|      1|         return if_match(oid, {1, 2, 840, 10045, 3, 1, 5}, "x962_p239v2");
  730|      1|      case 0xC9C55:
  ------------------
  |  Branch (730:7): [True: 1, False: 1.32k]
  ------------------
  731|      1|         return if_match(oid, {1, 2, 840, 10045, 3, 1, 6}, "x962_p239v3");
  732|      1|      case 0xC9C56:
  ------------------
  |  Branch (732:7): [True: 1, False: 1.32k]
  ------------------
  733|      1|         return if_match(oid, {1, 2, 840, 10045, 3, 1, 7}, "secp256r1");
  734|      1|      case 0xCFA13:
  ------------------
  |  Branch (734:7): [True: 1, False: 1.32k]
  ------------------
  735|      1|         return if_match(oid, {1, 2, 840, 10040, 4, 1}, "DSA");
  736|      1|      case 0xCFA15:
  ------------------
  |  Branch (736:7): [True: 1, False: 1.32k]
  ------------------
  737|      1|         return if_match(oid, {1, 2, 840, 10040, 4, 3}, "DSA/SHA-1");
  738|    979|      default:
  ------------------
  |  Branch (738:7): [True: 979, False: 342]
  ------------------
  739|    979|         return {};
  740|  1.32k|   }
  741|  1.32k|}
_ZN5Botan7OID_Map22lookup_static_oid_nameENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  744|  1.32k|std::optional<OID> OID_Map::lookup_static_oid_name(std::string_view req) {
  745|  1.32k|   const uint32_t hc = hash_oid_name(req);
  746|       |
  747|  1.32k|   switch(hc) {
  748|      0|      case 0x00545:
  ------------------
  |  Branch (748:7): [True: 0, False: 1.32k]
  ------------------
  749|      0|         return if_match(req, "Twofish/GCM", {1, 3, 6, 1, 4, 1, 25258, 3, 102});
  750|      0|      case 0x00CF3:
  ------------------
  |  Branch (750:7): [True: 0, False: 1.32k]
  ------------------
  751|      0|         return if_match(req, "SphincsPlus-sha2-192f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 4});
  752|      0|      case 0x015FE:
  ------------------
  |  Branch (752:7): [True: 0, False: 1.32k]
  ------------------
  753|      0|         return if_match(req, "FrodoKEM-640-SHAKE", {1, 3, 6, 1, 4, 1, 25258, 1, 14, 1});
  754|      0|      case 0x01F9E:
  ------------------
  |  Branch (754:7): [True: 0, False: 1.32k]
  ------------------
  755|      0|         return if_match(req, "MD5", {1, 2, 840, 113549, 2, 5});
  756|      0|      case 0x02293:
  ------------------
  |  Branch (756:7): [True: 0, False: 1.32k]
  ------------------
  757|      0|         return if_match(req, "SphincsPlus-shake-192f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 4});
  758|      0|      case 0x02B93:
  ------------------
  |  Branch (758:7): [True: 0, False: 1.32k]
  ------------------
  759|      0|         return if_match(req, "Microsoft SmartcardLogon", {1, 3, 6, 1, 4, 1, 311, 20, 2, 2});
  760|      0|      case 0x041D5:
  ------------------
  |  Branch (760:7): [True: 0, False: 1.32k]
  ------------------
  761|      0|         return if_match(req, "secp160k1", {1, 3, 132, 0, 9});
  762|      0|      case 0x044B3:
  ------------------
  |  Branch (762:7): [True: 0, False: 1.32k]
  ------------------
  763|      0|         return if_match(req, "Camellia-256/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 8});
  764|      0|      case 0x048B2:
  ------------------
  |  Branch (764:7): [True: 0, False: 1.32k]
  ------------------
  765|      0|         return if_match(req, "secp160r1", {1, 3, 132, 0, 8});
  766|      0|      case 0x048B3:
  ------------------
  |  Branch (766:7): [True: 0, False: 1.32k]
  ------------------
  767|      0|         return if_match(req, "secp160r2", {1, 3, 132, 0, 30});
  768|      0|      case 0x05CDA:
  ------------------
  |  Branch (768:7): [True: 0, False: 1.32k]
  ------------------
  769|      0|         return if_match(req, "X520.Country", {2, 5, 4, 6});
  770|      0|      case 0x07783:
  ------------------
  |  Branch (770:7): [True: 0, False: 1.32k]
  ------------------
  771|      0|         return if_match(req, "PKIX.ServerAuth", {1, 3, 6, 1, 5, 5, 7, 3, 1});
  772|      0|      case 0x086C7:
  ------------------
  |  Branch (772:7): [True: 0, False: 1.32k]
  ------------------
  773|      0|         return if_match(req, "numsp384d1", {1, 3, 6, 1, 4, 1, 25258, 4, 2});
  774|      0|      case 0x08A92:
  ------------------
  |  Branch (774:7): [True: 0, False: 1.32k]
  ------------------
  775|      0|         return if_match(req, "RSA/PKCS1v15(SHA-1)", {1, 2, 840, 113549, 1, 1, 5});
  776|      0|      case 0x09EA0:
  ------------------
  |  Branch (776:7): [True: 0, False: 1.32k]
  ------------------
  777|      0|         return if_match(req, "DES/CBC", {1, 3, 14, 3, 2, 7});
  778|      0|      case 0x0B2D6:
  ------------------
  |  Branch (778:7): [True: 0, False: 1.32k]
  ------------------
  779|      0|         return if_match(req, "ECDSA/SHA-3(512)", {2, 16, 840, 1, 101, 3, 4, 3, 12});
  780|      0|      case 0x0BA72:
  ------------------
  |  Branch (780:7): [True: 0, False: 1.32k]
  ------------------
  781|      0|         return if_match(req, "SphincsPlus-sha2-128s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 1});
  782|      0|      case 0x0BE23:
  ------------------
  |  Branch (782:7): [True: 0, False: 1.32k]
  ------------------
  783|      0|         return if_match(req, "ECGDSA", {1, 3, 36, 3, 3, 2, 5, 2, 1});
  784|      0|      case 0x0C109:
  ------------------
  |  Branch (784:7): [True: 0, False: 1.32k]
  ------------------
  785|      0|         return if_match(req, "PKCS9.FriendlyName", {1, 2, 840, 113549, 1, 9, 20});
  786|      0|      case 0x0D012:
  ------------------
  |  Branch (786:7): [True: 0, False: 1.32k]
  ------------------
  787|      0|         return if_match(req, "SphincsPlus-shake-128s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 1});
  788|      0|      case 0x0DCE9:
  ------------------
  |  Branch (788:7): [True: 0, False: 1.32k]
  ------------------
  789|      0|         return if_match(req, "ClassicMcEliece_8192128f", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 10});
  790|      0|      case 0x0E52A:
  ------------------
  |  Branch (790:7): [True: 0, False: 1.32k]
  ------------------
  791|      0|         return if_match(req, "numsp512d1", {1, 3, 6, 1, 4, 1, 25258, 4, 3});
  792|      0|      case 0x0F9CC:
  ------------------
  |  Branch (792:7): [True: 0, False: 1.32k]
  ------------------
  793|      0|         return if_match(req, "PKCS9.UnstructuredName", {1, 2, 840, 113549, 1, 9, 2});
  794|      0|      case 0x0FF45:
  ------------------
  |  Branch (794:7): [True: 0, False: 1.32k]
  ------------------
  795|      0|         return if_match(req, "Camellia-256/GCM", {0, 3, 4401, 5, 3, 1, 9, 46});
  796|      0|      case 0x1033D:
  ------------------
  |  Branch (796:7): [True: 0, False: 1.32k]
  ------------------
  797|      0|         return if_match(req, "DSA/SHA-3(384)", {2, 16, 840, 1, 101, 3, 4, 3, 7});
  798|      0|      case 0x1139D:
  ------------------
  |  Branch (798:7): [True: 0, False: 1.32k]
  ------------------
  799|      0|         return if_match(req, "secp192k1", {1, 3, 132, 0, 31});
  800|      0|      case 0x113D6:
  ------------------
  |  Branch (800:7): [True: 0, False: 1.32k]
  ------------------
  801|      0|         return if_match(req, "X520.DNQualifier", {2, 5, 4, 46});
  802|      0|      case 0x11A7A:
  ------------------
  |  Branch (802:7): [True: 0, False: 1.32k]
  ------------------
  803|      0|         return if_match(req, "secp192r1", {1, 2, 840, 10045, 3, 1, 1});
  804|      0|      case 0x12096:
  ------------------
  |  Branch (804:7): [True: 0, False: 1.32k]
  ------------------
  805|      0|         return if_match(req, "SM2_Kex", {1, 2, 156, 10197, 1, 301, 2});
  806|      0|      case 0x13FC1:
  ------------------
  |  Branch (806:7): [True: 0, False: 1.32k]
  ------------------
  807|      0|         return if_match(req, "X520.GenerationalQualifier", {2, 5, 4, 44});
  808|      0|      case 0x1445B:
  ------------------
  |  Branch (808:7): [True: 0, False: 1.32k]
  ------------------
  809|      0|         return if_match(req, "PKCS5.PBKDF2", {1, 2, 840, 113549, 1, 5, 12});
  810|      0|      case 0x1495D:
  ------------------
  |  Branch (810:7): [True: 0, False: 1.32k]
  ------------------
  811|      0|         return if_match(req, "eFrodoKEM-1344-AES", {1, 3, 6, 1, 4, 1, 25258, 1, 17, 3});
  812|      0|      case 0x14E30:
  ------------------
  |  Branch (812:7): [True: 0, False: 1.32k]
  ------------------
  813|      0|         return if_match(req, "ClassicMcEliece_460896", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 3});
  814|      0|      case 0x14FB1:
  ------------------
  |  Branch (814:7): [True: 0, False: 1.32k]
  ------------------
  815|      0|         return if_match(req, "XMSS-draft12", {1, 3, 6, 1, 4, 1, 25258, 1, 8});
  816|      0|      case 0x156E3:
  ------------------
  |  Branch (816:7): [True: 0, False: 1.32k]
  ------------------
  817|      0|         return if_match(req, "Compression.Zlib", {1, 2, 840, 113549, 1, 9, 16, 3, 8});
  818|      0|      case 0x1579E:
  ------------------
  |  Branch (818:7): [True: 0, False: 1.32k]
  ------------------
  819|      0|         return if_match(req, "Streebog-512", {1, 2, 643, 7, 1, 1, 2, 3});
  820|      0|      case 0x1701A:
  ------------------
  |  Branch (820:7): [True: 0, False: 1.32k]
  ------------------
  821|      0|         return if_match(req, "X509v3.AnyExtendedKeyUsage", {2, 5, 29, 37, 0});
  822|      0|      case 0x175EF:
  ------------------
  |  Branch (822:7): [True: 0, False: 1.32k]
  ------------------
  823|      0|         return if_match(req, "Kyber-1024-90s-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 11, 3});
  824|      0|      case 0x17709:
  ------------------
  |  Branch (824:7): [True: 0, False: 1.32k]
  ------------------
  825|      0|         return if_match(req, "X520.GivenName", {2, 5, 4, 42});
  826|      0|      case 0x17AD9:
  ------------------
  |  Branch (826:7): [True: 0, False: 1.32k]
  ------------------
  827|      0|         return if_match(req, "RSA/PKCS1v15(SM3)", {1, 2, 156, 10197, 1, 504});
  828|      0|      case 0x17CE2:
  ------------------
  |  Branch (828:7): [True: 0, False: 1.32k]
  ------------------
  829|      0|         return if_match(req, "SLH-DSA-SHA2-256f", {2, 16, 840, 1, 101, 3, 4, 3, 25});
  830|      0|      case 0x17CEF:
  ------------------
  |  Branch (830:7): [True: 0, False: 1.32k]
  ------------------
  831|      0|         return if_match(req, "SLH-DSA-SHA2-256s", {2, 16, 840, 1, 101, 3, 4, 3, 24});
  832|      0|      case 0x18618:
  ------------------
  |  Branch (832:7): [True: 0, False: 1.32k]
  ------------------
  833|      0|         return if_match(req, "FrodoKEM-976-AES", {1, 3, 6, 1, 4, 1, 25258, 1, 15, 2});
  834|      0|      case 0x19480:
  ------------------
  |  Branch (834:7): [True: 0, False: 1.32k]
  ------------------
  835|      0|         return if_match(req, "eFrodoKEM-1344-SHAKE", {1, 3, 6, 1, 4, 1, 25258, 1, 16, 3});
  836|      0|      case 0x1958A:
  ------------------
  |  Branch (836:7): [True: 0, False: 1.32k]
  ------------------
  837|      0|         return if_match(req, "X509v3.InvalidityDate", {2, 5, 29, 24});
  838|      0|      case 0x19851:
  ------------------
  |  Branch (838:7): [True: 0, False: 1.32k]
  ------------------
  839|      0|         return if_match(req, "DSA/SHA-1", {1, 2, 840, 10040, 4, 3});
  840|      0|      case 0x1B2E7:
  ------------------
  |  Branch (840:7): [True: 0, False: 1.32k]
  ------------------
  841|      0|         return if_match(req, "KeyWrap.AES-128", {2, 16, 840, 1, 101, 3, 4, 1, 5});
  842|      0|      case 0x1B9BE:
  ------------------
  |  Branch (842:7): [True: 0, False: 1.32k]
  ------------------
  843|      0|         return if_match(req, "KeyWrap.AES-192", {2, 16, 840, 1, 101, 3, 4, 1, 25});
  844|      0|      case 0x1D439:
  ------------------
  |  Branch (844:7): [True: 0, False: 1.32k]
  ------------------
  845|      0|         return if_match(req, "SphincsPlus-haraka-192f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 4});
  846|      0|      case 0x2065B:
  ------------------
  |  Branch (846:7): [True: 0, False: 1.32k]
  ------------------
  847|      0|         return if_match(req, "KeyWrap.CAST-128", {1, 2, 840, 113533, 7, 66, 15});
  848|      0|      case 0x216A0:
  ------------------
  |  Branch (848:7): [True: 0, False: 1.32k]
  ------------------
  849|      0|         return if_match(req, "ML-KEM-512", {2, 16, 840, 1, 101, 3, 4, 4, 1});
  850|      0|      case 0x2216B:
  ------------------
  |  Branch (850:7): [True: 0, False: 1.32k]
  ------------------
  851|      0|         return if_match(req, "GOST-34.10-2012-512", {1, 2, 643, 7, 1, 1, 1, 2});
  852|      0|      case 0x22C2C:
  ------------------
  |  Branch (852:7): [True: 0, False: 1.32k]
  ------------------
  853|      0|         return if_match(req, "ElGamal", {1, 3, 6, 1, 4, 1, 3029, 1, 2, 1});
  854|      0|      case 0x2559A:
  ------------------
  |  Branch (854:7): [True: 0, False: 1.32k]
  ------------------
  855|      0|         return if_match(req, "X520.Initials", {2, 5, 4, 43});
  856|      0|      case 0x271AC:
  ------------------
  |  Branch (856:7): [True: 0, False: 1.32k]
  ------------------
  857|      0|         return if_match(req, "PKIX.AutonomousSysIds", {1, 3, 6, 1, 5, 5, 7, 1, 8});
  858|      0|      case 0x2808B:
  ------------------
  |  Branch (858:7): [True: 0, False: 1.32k]
  ------------------
  859|      0|         return if_match(req, "PKCS7.Data", {1, 2, 840, 113549, 1, 7, 1});
  860|      0|      case 0x281B8:
  ------------------
  |  Branch (860:7): [True: 0, False: 1.32k]
  ------------------
  861|      0|         return if_match(req, "SphincsPlus-haraka-128s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 1});
  862|      0|      case 0x282FE:
  ------------------
  |  Branch (862:7): [True: 0, False: 1.32k]
  ------------------
  863|      0|         return if_match(req, "PKIX.OCSP.Nonce", {1, 3, 6, 1, 5, 5, 7, 48, 1, 2});
  864|      0|      case 0x29999:
  ------------------
  |  Branch (864:7): [True: 0, False: 1.32k]
  ------------------
  865|      0|         return if_match(req, "DSA/SHA-3(256)", {2, 16, 840, 1, 101, 3, 4, 3, 6});
  866|      0|      case 0x2A83D:
  ------------------
  |  Branch (866:7): [True: 0, False: 1.32k]
  ------------------
  867|      0|         return if_match(req, "SHA-224", {2, 16, 840, 1, 101, 3, 4, 2, 4});
  868|      0|      case 0x2AB30:
  ------------------
  |  Branch (868:7): [True: 0, False: 1.32k]
  ------------------
  869|      0|         return if_match(req, "SHA-256", {2, 16, 840, 1, 101, 3, 4, 2, 1});
  870|      0|      case 0x2ABEF:
  ------------------
  |  Branch (870:7): [True: 0, False: 1.32k]
  ------------------
  871|      0|         return if_match(req, "KeyWrap.AES-256", {2, 16, 840, 1, 101, 3, 4, 1, 45});
  872|      0|      case 0x2BAEF:
  ------------------
  |  Branch (872:7): [True: 0, False: 1.32k]
  ------------------
  873|      0|         return if_match(req, "SM2_Sig/SM3", {1, 2, 156, 10197, 1, 501});
  874|      0|      case 0x2C39A:
  ------------------
  |  Branch (874:7): [True: 0, False: 1.32k]
  ------------------
  875|      0|         return if_match(req, "ECGDSA/RIPEMD-160", {1, 3, 36, 3, 3, 2, 5, 4, 1});
  876|      0|      case 0x2C54F:
  ------------------
  |  Branch (876:7): [True: 0, False: 1.32k]
  ------------------
  877|      0|         return if_match(req, "ECDSA/SHA-3(224)", {2, 16, 840, 1, 101, 3, 4, 3, 9});
  878|      0|      case 0x2EEA6:
  ------------------
  |  Branch (878:7): [True: 0, False: 1.32k]
  ------------------
  879|      0|         return if_match(req, "RSA/PKCS1v15(RIPEMD-160)", {1, 3, 36, 3, 3, 1, 2});
  880|      0|      case 0x2EFBA:
  ------------------
  |  Branch (880:7): [True: 0, False: 1.32k]
  ------------------
  881|      0|         return if_match(req, "Kyber-512-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 7, 1});
  882|      0|      case 0x2F0AD:
  ------------------
  |  Branch (882:7): [True: 0, False: 1.32k]
  ------------------
  883|      0|         return if_match(req, "PKCS7.EncryptedData", {1, 2, 840, 113549, 1, 7, 6});
  884|      0|      case 0x2F219:
  ------------------
  |  Branch (884:7): [True: 0, False: 1.32k]
  ------------------
  885|      0|         return if_match(req, "PBE-SHA1-2DES", {1, 2, 840, 113549, 1, 12, 1, 4});
  886|      0|      case 0x3133E:
  ------------------
  |  Branch (886:7): [True: 0, False: 1.32k]
  ------------------
  887|      0|         return if_match(req, "SLH-DSA-SHA2-128f", {2, 16, 840, 1, 101, 3, 4, 3, 21});
  888|      0|      case 0x3134B:
  ------------------
  |  Branch (888:7): [True: 0, False: 1.32k]
  ------------------
  889|      0|         return if_match(req, "SLH-DSA-SHA2-128s", {2, 16, 840, 1, 101, 3, 4, 3, 20});
  890|      0|      case 0x3160D:
  ------------------
  |  Branch (890:7): [True: 0, False: 1.32k]
  ------------------
  891|      0|         return if_match(req, "RSA/PKCS1v15(SHA-3(224))", {2, 16, 840, 1, 101, 3, 4, 3, 13});
  892|      0|      case 0x319E0:
  ------------------
  |  Branch (892:7): [True: 0, False: 1.32k]
  ------------------
  893|      0|         return if_match(req, "GOST-34.10-2012-256/Streebog-256", {1, 2, 643, 7, 1, 1, 3, 2});
  894|      0|      case 0x31B3D:
  ------------------
  |  Branch (894:7): [True: 0, False: 1.32k]
  ------------------
  895|      0|         return if_match(req, "HMAC(SHA-512)", {1, 2, 840, 113549, 2, 11});
  896|      0|      case 0x31C6D:
  ------------------
  |  Branch (896:7): [True: 0, False: 1.32k]
  ------------------
  897|      0|         return if_match(req, "secp384r1", {1, 3, 132, 0, 34});
  898|      0|      case 0x32899:
  ------------------
  |  Branch (898:7): [True: 0, False: 1.32k]
  ------------------
  899|      0|         return if_match(req, "TripleDES/CBC", {1, 2, 840, 113549, 3, 7});
  900|      0|      case 0x33C9C:
  ------------------
  |  Branch (900:7): [True: 0, False: 1.32k]
  ------------------
  901|      0|         return if_match(req, "PKIX.SmtpUTF8Mailbox", {1, 3, 6, 1, 5, 5, 7, 8, 9});
  902|      0|      case 0x33D04:
  ------------------
  |  Branch (902:7): [True: 0, False: 1.32k]
  ------------------
  903|      0|         return if_match(req, "PKCS12.SecretBag", {1, 2, 840, 113549, 1, 12, 10, 1, 5});
  904|      0|      case 0x3615D:
  ------------------
  |  Branch (904:7): [True: 0, False: 1.32k]
  ------------------
  905|      0|         return if_match(req, "FrodoKEM-976-SHAKE", {1, 3, 6, 1, 4, 1, 25258, 1, 14, 2});
  906|      0|      case 0x361B8:
  ------------------
  |  Branch (906:7): [True: 0, False: 1.32k]
  ------------------
  907|      0|         return if_match(req, "Ed25519", {1, 3, 101, 112});
  908|      0|      case 0x3649D:
  ------------------
  |  Branch (908:7): [True: 0, False: 1.32k]
  ------------------
  909|      0|         return if_match(req, "SHAKE-128", {2, 16, 840, 1, 101, 3, 4, 2, 11});
  910|      0|      case 0x36693:
  ------------------
  |  Branch (910:7): [True: 0, False: 1.32k]
  ------------------
  911|      0|         return if_match(req, "ClassicMcEliece_348864", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 1});
  912|      0|      case 0x373C7:
  ------------------
  |  Branch (912:7): [True: 0, False: 1.32k]
  ------------------
  913|      0|         return if_match(req, "ML-DSA-4x4", {2, 16, 840, 1, 101, 3, 4, 3, 17});
  914|      0|      case 0x3750B:
  ------------------
  |  Branch (914:7): [True: 0, False: 1.32k]
  ------------------
  915|      0|         return if_match(req, "ClassicMcEliece_8192128", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 9});
  916|      0|      case 0x39890:
  ------------------
  |  Branch (916:7): [True: 0, False: 1.32k]
  ------------------
  917|      0|         return if_match(req, "Ed448", {1, 3, 101, 113});
  918|      0|      case 0x3A438:
  ------------------
  |  Branch (918:7): [True: 0, False: 1.32k]
  ------------------
  919|      0|         return if_match(req, "SHA-384", {2, 16, 840, 1, 101, 3, 4, 2, 2});
  920|      0|      case 0x3A963:
  ------------------
  |  Branch (920:7): [True: 0, False: 1.32k]
  ------------------
  921|      0|         return if_match(req, "DH", {1, 2, 840, 10046, 2, 1});
  922|      0|      case 0x3AC83:
  ------------------
  |  Branch (922:7): [True: 0, False: 1.32k]
  ------------------
  923|      0|         return if_match(req, "MGF1", {1, 2, 840, 113549, 1, 1, 8});
  924|      0|      case 0x3ACBA:
  ------------------
  |  Branch (924:7): [True: 0, False: 1.32k]
  ------------------
  925|      0|         return if_match(req, "X509v3.IssuerAlternativeName", {2, 5, 29, 18});
  926|      0|      case 0x3B273:
  ------------------
  |  Branch (926:7): [True: 0, False: 1.32k]
  ------------------
  927|      0|         return if_match(req, "KeyWrap.TripleDES", {1, 2, 840, 113549, 1, 9, 16, 3, 6});
  928|      0|      case 0x3B91E:
  ------------------
  |  Branch (928:7): [True: 0, False: 1.32k]
  ------------------
  929|      0|         return if_match(req, "X509v3.PrivateKeyUsagePeriod", {2, 5, 29, 16});
  930|      0|      case 0x3BC8A:
  ------------------
  |  Branch (930:7): [True: 0, False: 1.32k]
  ------------------
  931|      0|         return if_match(req, "SLH-DSA-SHAKE-192f", {2, 16, 840, 1, 101, 3, 4, 3, 29});
  932|      0|      case 0x3BC97:
  ------------------
  |  Branch (932:7): [True: 0, False: 1.32k]
  ------------------
  933|      0|         return if_match(req, "SLH-DSA-SHAKE-192s", {2, 16, 840, 1, 101, 3, 4, 3, 28});
  934|      0|      case 0x3D127:
  ------------------
  |  Branch (934:7): [True: 0, False: 1.32k]
  ------------------
  935|      0|         return if_match(req, "DSA", {1, 2, 840, 10040, 4, 1});
  936|      0|      case 0x3E249:
  ------------------
  |  Branch (936:7): [True: 0, False: 1.32k]
  ------------------
  937|      0|         return if_match(req, "HSS-LMS", {1, 2, 840, 113549, 1, 9, 16, 3, 17});
  938|      0|      case 0x3E7D5:
  ------------------
  |  Branch (938:7): [True: 0, False: 1.32k]
  ------------------
  939|      0|         return if_match(req, "RSA/PKCS1v15(SHA-3(256))", {2, 16, 840, 1, 101, 3, 4, 3, 14});
  940|      0|      case 0x3F748:
  ------------------
  |  Branch (940:7): [True: 0, False: 1.32k]
  ------------------
  941|      0|         return if_match(req, "GOST.OGRN", {1, 2, 643, 100, 1});
  942|      0|      case 0x3F99F:
  ------------------
  |  Branch (942:7): [True: 0, False: 1.32k]
  ------------------
  943|      0|         return if_match(req, "X509v3.BasicConstraints", {2, 5, 29, 19});
  944|      0|      case 0x40726:
  ------------------
  |  Branch (944:7): [True: 0, False: 1.32k]
  ------------------
  945|      0|         return if_match(req, "SHA-3(512)", {2, 16, 840, 1, 101, 3, 4, 2, 10});
  946|      0|      case 0x407BF:
  ------------------
  |  Branch (946:7): [True: 0, False: 1.32k]
  ------------------
  947|      0|         return if_match(req, "ML-KEM-768", {2, 16, 840, 1, 101, 3, 4, 4, 2});
  948|      0|      case 0x41334:
  ------------------
  |  Branch (948:7): [True: 0, False: 1.32k]
  ------------------
  949|      0|         return if_match(req, "ECDSA/SHA-3(384)", {2, 16, 840, 1, 101, 3, 4, 3, 11});
  950|      0|      case 0x42DF3:
  ------------------
  |  Branch (950:7): [True: 0, False: 1.32k]
  ------------------
  951|      0|         return if_match(req, "X509v3.CRLDistributionPoints", {2, 5, 29, 31});
  952|      0|      case 0x437FB:
  ------------------
  |  Branch (952:7): [True: 0, False: 1.32k]
  ------------------
  953|      0|         return if_match(req, "brainpool160r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 1});
  954|      0|      case 0x441F5:
  ------------------
  |  Branch (954:7): [True: 0, False: 1.32k]
  ------------------
  955|      0|         return if_match(req, "gost_256A", {1, 2, 643, 7, 1, 2, 1, 1, 1});
  956|      0|      case 0x441F6:
  ------------------
  |  Branch (956:7): [True: 0, False: 1.32k]
  ------------------
  957|      0|         return if_match(req, "gost_256B", {1, 2, 643, 7, 1, 2, 1, 1, 2});
  958|      0|      case 0x44221:
  ------------------
  |  Branch (958:7): [True: 0, False: 1.32k]
  ------------------
  959|      0|         return if_match(req, "GOST-34.10-2012-512/Streebog-512", {1, 2, 643, 7, 1, 1, 3, 3});
  960|      0|      case 0x44322:
  ------------------
  |  Branch (960:7): [True: 0, False: 1.32k]
  ------------------
  961|      0|         return if_match(req, "ClassicMcEliece_6960119pc", {1, 3, 6, 1, 4, 1, 25258, 1, 18, 3});
  962|      0|      case 0x44973:
  ------------------
  |  Branch (962:7): [True: 0, False: 1.32k]
  ------------------
  963|      0|         return if_match(req, "Kyber-512-90s-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 11, 1});
  964|      0|      case 0x45C27:
  ------------------
  |  Branch (964:7): [True: 0, False: 1.32k]
  ------------------
  965|      0|         return if_match(req, "RSA/PKCS1v15(SHA-512-256)", {1, 2, 840, 113549, 1, 1, 16});
  966|      0|      case 0x45C85:
  ------------------
  |  Branch (966:7): [True: 0, False: 1.32k]
  ------------------
  967|      0|         return if_match(req, "X509v3.ReasonCode", {2, 5, 29, 21});
  968|      0|      case 0x45DA5:
  ------------------
  |  Branch (968:7): [True: 0, False: 1.32k]
  ------------------
  969|      0|         return if_match(req, "SHAKE-256", {2, 16, 840, 1, 101, 3, 4, 2, 12});
  970|      0|      case 0x4663C:
  ------------------
  |  Branch (970:7): [True: 0, False: 1.32k]
  ------------------
  971|      0|         return if_match(req, "X509v3.PolicyConstraints", {2, 5, 29, 36});
  972|      0|      case 0x480F7:
  ------------------
  |  Branch (972:7): [True: 0, False: 1.32k]
  ------------------
  973|      0|         return if_match(req, "Serpent/OCB", {1, 3, 6, 1, 4, 1, 25258, 3, 2, 4});
  974|      0|      case 0x48627:
  ------------------
  |  Branch (974:7): [True: 0, False: 1.32k]
  ------------------
  975|      0|         return if_match(req, "Dilithium-4x4-AES-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 10, 1});
  976|      0|      case 0x48861:
  ------------------
  |  Branch (976:7): [True: 0, False: 1.32k]
  ------------------
  977|      0|         return if_match(req, "ChaCha20Poly1305", {1, 2, 840, 113549, 1, 9, 16, 3, 18});
  978|      0|      case 0x4A292:
  ------------------
  |  Branch (978:7): [True: 0, False: 1.32k]
  ------------------
  979|      0|         return if_match(req, "frp256v1", {1, 2, 250, 1, 223, 101, 256, 1});
  980|      0|      case 0x4A9EE:
  ------------------
  |  Branch (980:7): [True: 0, False: 1.32k]
  ------------------
  981|      0|         return if_match(req, "ClassicMcEliece_6960119f", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 8});
  982|      0|      case 0x4BF87:
  ------------------
  |  Branch (982:7): [True: 0, False: 1.32k]
  ------------------
  983|      0|         return if_match(req, "PKIX.TNAuthList", {1, 3, 6, 1, 5, 5, 7, 1, 26});
  984|      0|      case 0x4C088:
  ------------------
  |  Branch (984:7): [True: 0, False: 1.32k]
  ------------------
  985|      0|         return if_match(req, "eFrodoKEM-976-AES", {1, 3, 6, 1, 4, 1, 25258, 1, 17, 2});
  986|      0|      case 0x4C513:
  ------------------
  |  Branch (986:7): [True: 0, False: 1.32k]
  ------------------
  987|      0|         return if_match(req, "DSA/SHA-224", {2, 16, 840, 1, 101, 3, 4, 3, 1});
  988|      0|      case 0x4C806:
  ------------------
  |  Branch (988:7): [True: 0, False: 1.32k]
  ------------------
  989|      0|         return if_match(req, "DSA/SHA-256", {2, 16, 840, 1, 101, 3, 4, 3, 2});
  990|      0|      case 0x4D740:
  ------------------
  |  Branch (990:7): [True: 0, False: 1.32k]
  ------------------
  991|      0|         return if_match(req, "X509v3.AnyPolicy", {2, 5, 29, 32, 0});
  992|      0|      case 0x4DE49:
  ------------------
  |  Branch (992:7): [True: 0, False: 1.32k]
  ------------------
  993|      0|         return if_match(req, "RSA/PKCS1v15(SHA-512)", {1, 2, 840, 113549, 1, 1, 13});
  994|      0|      case 0x4ED5D:
  ------------------
  |  Branch (994:7): [True: 0, False: 1.32k]
  ------------------
  995|      0|         return if_match(req, "CAST-128/CBC", {1, 2, 840, 113533, 7, 66, 10});
  996|      0|      case 0x4FCDC:
  ------------------
  |  Branch (996:7): [True: 0, False: 1.32k]
  ------------------
  997|      0|         return if_match(req, "RSA", {1, 2, 840, 113549, 1, 1, 1});
  998|      0|      case 0x501CB:
  ------------------
  |  Branch (998:7): [True: 0, False: 1.32k]
  ------------------
  999|      0|         return if_match(req, "ECDSA/SHA-224", {1, 2, 840, 10045, 4, 3, 1});
 1000|      0|      case 0x50395:
  ------------------
  |  Branch (1000:7): [True: 0, False: 1.32k]
  ------------------
 1001|      0|         return if_match(req, "GOST-34.10/GOST-R-34.11-94", {1, 2, 643, 2, 2, 3});
 1002|      0|      case 0x504BE:
  ------------------
  |  Branch (1002:7): [True: 0, False: 1.32k]
  ------------------
 1003|      0|         return if_match(req, "ECDSA/SHA-256", {1, 2, 840, 10045, 4, 3, 2});
 1004|      0|      case 0x509C3:
  ------------------
  |  Branch (1004:7): [True: 0, False: 1.32k]
  ------------------
 1005|      0|         return if_match(req, "brainpool192r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 3});
 1006|      0|      case 0x509F9:
  ------------------
  |  Branch (1006:7): [True: 0, False: 1.32k]
  ------------------
 1007|      0|         return if_match(req, "PKCS9.ContentType", {1, 2, 840, 113549, 1, 9, 3});
 1008|      0|      case 0x50B26:
  ------------------
  |  Branch (1008:7): [True: 0, False: 1.32k]
  ------------------
 1009|      0|         return if_match(req, "FrodoKEM-640-AES", {1, 3, 6, 1, 4, 1, 25258, 1, 15, 1});
 1010|      0|      case 0x50D78:
  ------------------
  |  Branch (1010:7): [True: 0, False: 1.32k]
  ------------------
 1011|      0|         return if_match(req, "x962_p192v2", {1, 2, 840, 10045, 3, 1, 2});
 1012|      0|      case 0x50D79:
  ------------------
  |  Branch (1012:7): [True: 0, False: 1.32k]
  ------------------
 1013|      0|         return if_match(req, "x962_p192v3", {1, 2, 840, 10045, 3, 1, 3});
 1014|      0|      case 0x51DC6:
  ------------------
  |  Branch (1014:7): [True: 0, False: 1.32k]
  ------------------
 1015|      0|         return if_match(req, "AES-128/OCB", {1, 3, 6, 1, 4, 1, 25258, 3, 2, 1});
 1016|      0|      case 0x52DB6:
  ------------------
  |  Branch (1016:7): [True: 0, False: 1.32k]
  ------------------
 1017|      0|         return if_match(req, "HMAC(SHA-224)", {1, 2, 840, 113549, 2, 8});
 1018|      0|      case 0x53E11:
  ------------------
  |  Branch (1018:7): [True: 0, False: 1.32k]
  ------------------
 1019|      0|         return if_match(req, "FrodoKEM-1344-SHAKE", {1, 3, 6, 1, 4, 1, 25258, 1, 14, 3});
 1020|      0|      case 0x54012:
  ------------------
  |  Branch (1020:7): [True: 0, False: 1.32k]
  ------------------
 1021|      0|         return if_match(req, "PKIX.TimeStamping", {1, 3, 6, 1, 5, 5, 7, 3, 8});
 1022|      0|      case 0x5407A:
  ------------------
  |  Branch (1022:7): [True: 0, False: 1.32k]
  ------------------
 1023|      0|         return if_match(req, "Serpent/CBC", {1, 3, 6, 1, 4, 1, 25258, 3, 1});
 1024|      0|      case 0x5576D:
  ------------------
  |  Branch (1024:7): [True: 0, False: 1.32k]
  ------------------
 1025|      0|         return if_match(req, "SphincsPlus-sha2-128f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 2});
 1026|      0|      case 0x55EF6:
  ------------------
  |  Branch (1026:7): [True: 0, False: 1.32k]
  ------------------
 1027|      0|         return if_match(req, "AES-192/OCB", {1, 3, 6, 1, 4, 1, 25258, 3, 2, 2});
 1028|      0|      case 0x55FFA:
  ------------------
  |  Branch (1028:7): [True: 0, False: 1.32k]
  ------------------
 1029|      0|         return if_match(req, "ML-DSA-6x5", {2, 16, 840, 1, 101, 3, 4, 3, 18});
 1030|      0|      case 0x56826:
  ------------------
  |  Branch (1030:7): [True: 0, False: 1.32k]
  ------------------
 1031|      0|         return if_match(req, "brainpool320r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 9});
 1032|      0|      case 0x56D0D:
  ------------------
  |  Branch (1032:7): [True: 0, False: 1.32k]
  ------------------
 1033|      0|         return if_match(req, "SphincsPlus-shake-128f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 2});
 1034|      0|      case 0x57077:
  ------------------
  |  Branch (1034:7): [True: 0, False: 1.32k]
  ------------------
 1035|      0|         return if_match(req, "XMSS-draft6", {1, 3, 6, 1, 4, 1, 25258, 1, 5});
 1036|      0|      case 0x5818B:
  ------------------
  |  Branch (1036:7): [True: 0, False: 1.32k]
  ------------------
 1037|      0|         return if_match(req, "ECGDSA/SHA-224", {1, 3, 36, 3, 3, 2, 5, 4, 3});
 1038|      0|      case 0x5847E:
  ------------------
  |  Branch (1038:7): [True: 0, False: 1.32k]
  ------------------
 1039|      0|         return if_match(req, "ECGDSA/SHA-256", {1, 3, 36, 3, 3, 2, 5, 4, 4});
 1040|      0|      case 0x5898B:
  ------------------
  |  Branch (1040:7): [True: 0, False: 1.32k]
  ------------------
 1041|      0|         return if_match(req, "SHA-512", {2, 16, 840, 1, 101, 3, 4, 2, 3});
 1042|      0|      case 0x58991:
  ------------------
  |  Branch (1042:7): [True: 0, False: 1.32k]
  ------------------
 1043|      0|         return if_match(req, "PKIX.OCSP.NoCheck", {1, 3, 6, 1, 5, 5, 7, 48, 1, 5});
 1044|      0|      case 0x59717:
  ------------------
  |  Branch (1044:7): [True: 0, False: 1.32k]
  ------------------
 1045|      0|         return if_match(req, "X509v3.SubjectKeyIdentifier", {2, 5, 29, 14});
 1046|      0|      case 0x5A1E1:
  ------------------
  |  Branch (1046:7): [True: 0, False: 1.32k]
  ------------------
 1047|      0|         return if_match(req, "PKCS12.KeyBag", {1, 2, 840, 113549, 1, 12, 10, 1, 1});
 1048|      0|      case 0x5A570:
  ------------------
  |  Branch (1048:7): [True: 0, False: 1.32k]
  ------------------
 1049|      0|         return if_match(req, "X520.CommonName", {2, 5, 4, 3});
 1050|      0|      case 0x5A990:
  ------------------
  |  Branch (1050:7): [True: 0, False: 1.32k]
  ------------------
 1051|      0|         return if_match(req, "ECDSA/SHA-3(256)", {2, 16, 840, 1, 101, 3, 4, 3, 10});
 1052|      0|      case 0x5AB0E:
  ------------------
  |  Branch (1052:7): [True: 0, False: 1.32k]
  ------------------
 1053|      0|         return if_match(req, "SphincsPlus-sha2-256s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 5});
 1054|      0|      case 0x5AC4A:
  ------------------
  |  Branch (1054:7): [True: 0, False: 1.32k]
  ------------------
 1055|      0|         return if_match(req, "X520.Surname", {2, 5, 4, 4});
 1056|      0|      case 0x5AF2C:
  ------------------
  |  Branch (1056:7): [True: 0, False: 1.32k]
  ------------------
 1057|      0|         return if_match(req, "ClassicMcEliece_8192128pc", {1, 3, 6, 1, 4, 1, 25258, 1, 18, 5});
 1058|      0|      case 0x5BC39:
  ------------------
  |  Branch (1058:7): [True: 0, False: 1.32k]
  ------------------
 1059|      0|         return if_match(req, "X509v3.KeyUsage", {2, 5, 29, 15});
 1060|      0|      case 0x5BDDB:
  ------------------
  |  Branch (1060:7): [True: 0, False: 1.32k]
  ------------------
 1061|      0|         return if_match(req, "numsp256d1", {1, 3, 6, 1, 4, 1, 25258, 4, 1});
 1062|      0|      case 0x5C0AE:
  ------------------
  |  Branch (1062:7): [True: 0, False: 1.32k]
  ------------------
 1063|      0|         return if_match(req, "SphincsPlus-shake-256s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 5});
 1064|      0|      case 0x5C10E:
  ------------------
  |  Branch (1064:7): [True: 0, False: 1.32k]
  ------------------
 1065|      0|         return if_match(req, "DSA/SHA-384", {2, 16, 840, 1, 101, 3, 4, 3, 3});
 1066|      0|      case 0x5CFE5:
  ------------------
  |  Branch (1066:7): [True: 0, False: 1.32k]
  ------------------
 1067|      0|         return if_match(req, "PKCS9.X509Certificate", {1, 2, 840, 113549, 1, 9, 22, 1});
 1068|      0|      case 0x5D1CF:
  ------------------
  |  Branch (1068:7): [True: 0, False: 1.32k]
  ------------------
 1069|      0|         return if_match(req, "X520.SerialNumber", {2, 5, 4, 5});
 1070|      0|      case 0x5D375:
  ------------------
  |  Branch (1070:7): [True: 0, False: 1.32k]
  ------------------
 1071|      0|         return if_match(req, "SM4/OCB", {1, 2, 156, 10197, 1, 104, 100});
 1072|      0|      case 0x5DD49:
  ------------------
  |  Branch (1072:7): [True: 0, False: 1.32k]
  ------------------
 1073|      0|         return if_match(req, "AES-128/CBC", {2, 16, 840, 1, 101, 3, 4, 1, 2});
 1074|      0|      case 0x5DE4E:
  ------------------
  |  Branch (1074:7): [True: 0, False: 1.32k]
  ------------------
 1075|      0|         return if_match(req, "AES-128/CCM", {2, 16, 840, 1, 101, 3, 4, 1, 7});
 1076|      0|      case 0x5DF23:
  ------------------
  |  Branch (1076:7): [True: 0, False: 1.32k]
  ------------------
 1077|      0|         return if_match(req, "HMAC(SHA-512-256)", {1, 2, 840, 113549, 2, 13});
 1078|      0|      case 0x5ED04:
  ------------------
  |  Branch (1078:7): [True: 0, False: 1.32k]
  ------------------
 1079|      0|         return if_match(req, "SM2", {1, 2, 156, 10197, 1, 301, 1});
 1080|      0|      case 0x5ED05:
  ------------------
  |  Branch (1080:7): [True: 0, False: 1.32k]
  ------------------
 1081|      0|         return if_match(req, "SM3", {1, 2, 156, 10197, 1, 401});
 1082|      0|      case 0x5FDC6:
  ------------------
  |  Branch (1082:7): [True: 0, False: 1.32k]
  ------------------
 1083|      0|         return if_match(req, "ECDSA/SHA-384", {1, 2, 840, 10045, 4, 3, 3});
 1084|      0|      case 0x6199F:
  ------------------
  |  Branch (1084:7): [True: 0, False: 1.32k]
  ------------------
 1085|      0|         return if_match(req, "SHA-3(224)", {2, 16, 840, 1, 101, 3, 4, 2, 7});
 1086|      0|      case 0x61E79:
  ------------------
  |  Branch (1086:7): [True: 0, False: 1.32k]
  ------------------
 1087|      0|         return if_match(req, "AES-192/CBC", {2, 16, 840, 1, 101, 3, 4, 1, 22});
 1088|      0|      case 0x61F7E:
  ------------------
  |  Branch (1088:7): [True: 0, False: 1.32k]
  ------------------
 1089|      0|         return if_match(req, "AES-192/CCM", {2, 16, 840, 1, 101, 3, 4, 1, 27});
 1090|      0|      case 0x64947:
  ------------------
  |  Branch (1090:7): [True: 0, False: 1.32k]
  ------------------
 1091|      0|         return if_match(req, "OpenPGP.Ed25519", {1, 3, 6, 1, 4, 1, 11591, 15, 1});
 1092|      0|      case 0x652E7:
  ------------------
  |  Branch (1092:7): [True: 0, False: 1.32k]
  ------------------
 1093|      0|         return if_match(req, "sm2p256v1", {1, 2, 156, 10197, 1, 301});
 1094|      0|      case 0x6697B:
  ------------------
  |  Branch (1094:7): [True: 0, False: 1.32k]
  ------------------
 1095|      0|         return if_match(req, "FrodoKEM-1344-AES", {1, 3, 6, 1, 4, 1, 25258, 1, 15, 3});
 1096|      0|      case 0x67B2C:
  ------------------
  |  Branch (1096:7): [True: 0, False: 1.32k]
  ------------------
 1097|      0|         return if_match(req, "X520.State", {2, 5, 4, 8});
 1098|      0|      case 0x67B9B:
  ------------------
  |  Branch (1098:7): [True: 0, False: 1.32k]
  ------------------
 1099|      0|         return if_match(req, "HMAC(SHA-384)", {1, 2, 840, 113549, 2, 10});
 1100|      0|      case 0x67D86:
  ------------------
  |  Branch (1100:7): [True: 0, False: 1.32k]
  ------------------
 1101|      0|         return if_match(req, "ECGDSA/SHA-384", {1, 3, 36, 3, 3, 2, 5, 4, 5});
 1102|      0|      case 0x68A0B:
  ------------------
  |  Branch (1102:7): [True: 0, False: 1.32k]
  ------------------
 1103|      0|         return if_match(req, "Camellia-128/OCB", {1, 3, 6, 1, 4, 1, 25258, 3, 2, 6});
 1104|      0|      case 0x68E33:
  ------------------
  |  Branch (1104:7): [True: 0, False: 1.32k]
  ------------------
 1105|      0|         return if_match(req, "PKCS9.ExtensionRequest", {1, 2, 840, 113549, 1, 9, 14});
 1106|  1.32k|      case 0x69126:
  ------------------
  |  Branch (1106:7): [True: 1.32k, False: 0]
  ------------------
 1107|  1.32k|         return if_match(req, "X509v3.SubjectAlternativeName", {2, 5, 29, 17});
 1108|      0|      case 0x692F8:
  ------------------
  |  Branch (1108:7): [True: 0, False: 1.32k]
  ------------------
 1109|      0|         return if_match(req, "SM4/CBC", {1, 2, 156, 10197, 1, 104, 2});
 1110|      0|      case 0x695E1:
  ------------------
  |  Branch (1110:7): [True: 0, False: 1.32k]
  ------------------
 1111|      0|         return if_match(req, "Dilithium-4x4-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 9, 1});
 1112|      0|      case 0x696DC:
  ------------------
  |  Branch (1112:7): [True: 0, False: 1.32k]
  ------------------
 1113|      0|         return if_match(req, "PKIX.IpAddrBlocks", {1, 3, 6, 1, 5, 5, 7, 1, 7});
 1114|      0|      case 0x6A7CA:
  ------------------
  |  Branch (1114:7): [True: 0, False: 1.32k]
  ------------------
 1115|      0|         return if_match(req, "ECDSA", {1, 2, 840, 10045, 2, 1});
 1116|      0|      case 0x6BD26:
  ------------------
  |  Branch (1116:7): [True: 0, False: 1.32k]
  ------------------
 1117|      0|         return if_match(req, "GOST.INN", {1, 2, 643, 3, 131, 1, 1});
 1118|      0|      case 0x6CB3B:
  ------------------
  |  Branch (1118:7): [True: 0, False: 1.32k]
  ------------------
 1119|      0|         return if_match(req, "Camellia-192/OCB", {1, 3, 6, 1, 4, 1, 25258, 3, 2, 7});
 1120|      0|      case 0x6E602:
  ------------------
  |  Branch (1120:7): [True: 0, False: 1.32k]
  ------------------
 1121|      0|         return if_match(req, "Dilithium-8x7-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 9, 3});
 1122|      0|      case 0x6F0C2:
  ------------------
  |  Branch (1122:7): [True: 0, False: 1.32k]
  ------------------
 1123|      0|         return if_match(req, "RSA/PKCS1v15(SHA-224)", {1, 2, 840, 113549, 1, 1, 14});
 1124|      0|      case 0x6F9F8:
  ------------------
  |  Branch (1124:7): [True: 0, False: 1.32k]
  ------------------
 1125|      0|         return if_match(req, "PKCS12.SafeContentsBag", {1, 2, 840, 113549, 1, 12, 10, 1, 6});
 1126|      0|      case 0x6FB26:
  ------------------
  |  Branch (1126:7): [True: 0, False: 1.32k]
  ------------------
 1127|      0|         return if_match(req, "PKIX.AuthorityInformationAccess", {1, 3, 6, 1, 5, 5, 7, 1, 1});
 1128|      0|      case 0x70BB6:
  ------------------
  |  Branch (1128:7): [True: 0, False: 1.32k]
  ------------------
 1129|      0|         return if_match(req, "brainpool384r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 11});
 1130|      0|      case 0x70EA6:
  ------------------
  |  Branch (1130:7): [True: 0, False: 1.32k]
  ------------------
 1131|      0|         return if_match(req, "PKCS12.PKCS8ShroudedKeyBag", {1, 2, 840, 113549, 1, 12, 10, 1, 2});
 1132|      0|      case 0x71EB3:
  ------------------
  |  Branch (1132:7): [True: 0, False: 1.32k]
  ------------------
 1133|      0|         return if_match(req, "SphincsPlus-haraka-128f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 2});
 1134|      0|      case 0x7382C:
  ------------------
  |  Branch (1134:7): [True: 0, False: 1.32k]
  ------------------
 1135|      0|         return if_match(req, "ML-KEM-1024", {2, 16, 840, 1, 101, 3, 4, 4, 3});
 1136|      0|      case 0x743BD:
  ------------------
  |  Branch (1136:7): [True: 0, False: 1.32k]
  ------------------
 1137|      0|         return if_match(req, "AES-256/OCB", {1, 3, 6, 1, 4, 1, 25258, 3, 2, 3});
 1138|      0|      case 0x7498E:
  ------------------
  |  Branch (1138:7): [True: 0, False: 1.32k]
  ------------------
 1139|      0|         return if_match(req, "Camellia-128/CBC", {1, 2, 392, 200011, 61, 1, 1, 1, 2});
 1140|      0|      case 0x74C2E:
  ------------------
  |  Branch (1140:7): [True: 0, False: 1.32k]
  ------------------
 1141|      0|         return if_match(req, "ML-DSA-8x7", {2, 16, 840, 1, 101, 3, 4, 3, 19});
 1142|      0|      case 0x7505F:
  ------------------
  |  Branch (1142:7): [True: 0, False: 1.32k]
  ------------------
 1143|      0|         return if_match(req, "PKIX.XMPPAddr", {1, 3, 6, 1, 5, 5, 7, 8, 5});
 1144|      0|      case 0x7517A:
  ------------------
  |  Branch (1144:7): [True: 0, False: 1.32k]
  ------------------
 1145|      0|         return if_match(req, "RSA/PKCS1v15(MD2)", {1, 2, 840, 113549, 1, 1, 2});
 1146|      0|      case 0x7546B:
  ------------------
  |  Branch (1146:7): [True: 0, False: 1.32k]
  ------------------
 1147|      0|         return if_match(req, "RSA/PKCS1v15(MD5)", {1, 2, 840, 113549, 1, 1, 4});
 1148|      0|      case 0x75921:
  ------------------
  |  Branch (1148:7): [True: 0, False: 1.32k]
  ------------------
 1149|      0|         return if_match(req, "ClassicMcEliece_348864f", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 2});
 1150|      0|      case 0x76784:
  ------------------
  |  Branch (1150:7): [True: 0, False: 1.32k]
  ------------------
 1151|      0|         return if_match(req, "SHA-3(384)", {2, 16, 840, 1, 101, 3, 4, 2, 9});
 1152|      0|      case 0x768FD:
  ------------------
  |  Branch (1152:7): [True: 0, False: 1.32k]
  ------------------
 1153|      0|         return if_match(req, "PKCS9.LocalKeyId", {1, 2, 840, 113549, 1, 9, 21});
 1154|      0|      case 0x76A19:
  ------------------
  |  Branch (1154:7): [True: 0, False: 1.32k]
  ------------------
 1155|      0|         return if_match(req, "brainpool512r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 13});
 1156|      0|      case 0x77254:
  ------------------
  |  Branch (1156:7): [True: 0, False: 1.32k]
  ------------------
 1157|      0|         return if_match(req, "SphincsPlus-haraka-256s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 5});
 1158|      0|      case 0x77ADC:
  ------------------
  |  Branch (1158:7): [True: 0, False: 1.32k]
  ------------------
 1159|      0|         return if_match(req, "secp224k1", {1, 3, 132, 0, 32});
 1160|      0|      case 0x781B9:
  ------------------
  |  Branch (1160:7): [True: 0, False: 1.32k]
  ------------------
 1161|      0|         return if_match(req, "secp224r1", {1, 3, 132, 0, 33});
 1162|      0|      case 0x78ABE:
  ------------------
  |  Branch (1162:7): [True: 0, False: 1.32k]
  ------------------
 1163|      0|         return if_match(req, "Camellia-192/CBC", {1, 2, 392, 200011, 61, 1, 1, 1, 3});
 1164|      0|      case 0x792F2:
  ------------------
  |  Branch (1164:7): [True: 0, False: 1.32k]
  ------------------
 1165|      0|         return if_match(req, "ClassicMcEliece_6688128pc", {1, 3, 6, 1, 4, 1, 25258, 1, 18, 1});
 1166|      0|      case 0x7A661:
  ------------------
  |  Branch (1166:7): [True: 0, False: 1.32k]
  ------------------
 1167|      0|         return if_match(req, "DSA/SHA-512", {2, 16, 840, 1, 101, 3, 4, 3, 4});
 1168|      0|      case 0x7A977:
  ------------------
  |  Branch (1168:7): [True: 0, False: 1.32k]
  ------------------
 1169|      0|         return if_match(req, "X509v3.ExtendedKeyUsage", {2, 5, 29, 37});
 1170|      0|      case 0x7AE67:
  ------------------
  |  Branch (1170:7): [True: 0, False: 1.32k]
  ------------------
 1171|      0|         return if_match(req, "SM2_Enc", {1, 2, 156, 10197, 1, 301, 3});
 1172|      0|      case 0x7B602:
  ------------------
  |  Branch (1172:7): [True: 0, False: 1.32k]
  ------------------
 1173|      0|         return if_match(req, "Twofish/OCB", {1, 3, 6, 1, 4, 1, 25258, 3, 2, 5});
 1174|      0|      case 0x7B9A1:
  ------------------
  |  Branch (1174:7): [True: 0, False: 1.32k]
  ------------------
 1175|      0|         return if_match(req, "SphincsPlus-sha2-192s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 3});
 1176|      0|      case 0x7BB0A:
  ------------------
  |  Branch (1176:7): [True: 0, False: 1.32k]
  ------------------
 1177|      0|         return if_match(req, "SLH-DSA-SHAKE-256f", {2, 16, 840, 1, 101, 3, 4, 3, 31});
 1178|      0|      case 0x7BB17:
  ------------------
  |  Branch (1178:7): [True: 0, False: 1.32k]
  ------------------
 1179|      0|         return if_match(req, "SLH-DSA-SHAKE-256s", {2, 16, 840, 1, 101, 3, 4, 3, 30});
 1180|      0|      case 0x7BCF3:
  ------------------
  |  Branch (1180:7): [True: 0, False: 1.32k]
  ------------------
 1181|      0|         return if_match(req, "PKIX.EmailProtection", {1, 3, 6, 1, 5, 5, 7, 3, 4});
 1182|      0|      case 0x7CC2C:
  ------------------
  |  Branch (1182:7): [True: 0, False: 1.32k]
  ------------------
 1183|      0|         return if_match(req, "SHA-512-256", {2, 16, 840, 1, 101, 3, 4, 2, 6});
 1184|      0|      case 0x7CF41:
  ------------------
  |  Branch (1184:7): [True: 0, False: 1.32k]
  ------------------
 1185|      0|         return if_match(req, "SphincsPlus-shake-192s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 3});
 1186|      0|      case 0x7DB91:
  ------------------
  |  Branch (1186:7): [True: 0, False: 1.32k]
  ------------------
 1187|      0|         return if_match(req, "GOST-34.10", {1, 2, 643, 2, 2, 19});
 1188|      0|      case 0x7E319:
  ------------------
  |  Branch (1188:7): [True: 0, False: 1.32k]
  ------------------
 1189|      0|         return if_match(req, "ECDSA/SHA-512", {1, 2, 840, 10045, 4, 3, 4});
 1190|      0|      case 0x7E874:
  ------------------
  |  Branch (1190:7): [True: 0, False: 1.32k]
  ------------------
 1191|      0|         return if_match(req, "ClassicMcEliece_6688128f", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 6});
 1192|      0|      case 0x7EAAF:
  ------------------
  |  Branch (1192:7): [True: 0, False: 1.32k]
  ------------------
 1193|      0|         return if_match(req, "eFrodoKEM-640-SHAKE", {1, 3, 6, 1, 4, 1, 25258, 1, 16, 1});
 1194|      0|      case 0x7F51F:
  ------------------
  |  Branch (1194:7): [True: 0, False: 1.32k]
  ------------------
 1195|      0|         return if_match(req, "PKIX.IPsecTunnel", {1, 3, 6, 1, 5, 5, 7, 3, 6});
 1196|      0|      case 0x80272:
  ------------------
  |  Branch (1196:7): [True: 0, False: 1.32k]
  ------------------
 1197|      0|         return if_match(req, "X520.Organization", {2, 5, 4, 10});
 1198|      0|      case 0x80340:
  ------------------
  |  Branch (1198:7): [True: 0, False: 1.32k]
  ------------------
 1199|      0|         return if_match(req, "AES-256/CBC", {2, 16, 840, 1, 101, 3, 4, 1, 42});
 1200|      0|      case 0x80445:
  ------------------
  |  Branch (1200:7): [True: 0, False: 1.32k]
  ------------------
 1201|      0|         return if_match(req, "AES-256/CCM", {2, 16, 840, 1, 101, 3, 4, 1, 47});
 1202|      0|      case 0x811F7:
  ------------------
  |  Branch (1202:7): [True: 0, False: 1.32k]
  ------------------
 1203|      0|         return if_match(req, "HMAC(SHA-256)", {1, 2, 840, 113549, 2, 9});
 1204|      0|      case 0x82434:
  ------------------
  |  Branch (1204:7): [True: 0, False: 1.32k]
  ------------------
 1205|      0|         return if_match(req, "PKCS9.X509CRL", {1, 2, 840, 113549, 1, 9, 23, 1});
 1206|      0|      case 0x82B47:
  ------------------
  |  Branch (1206:7): [True: 0, False: 1.32k]
  ------------------
 1207|      0|         return if_match(req, "Threefish-512/CBC", {1, 3, 6, 1, 4, 1, 25258, 3, 2});
 1208|      0|      case 0x83EA7:
  ------------------
  |  Branch (1208:7): [True: 0, False: 1.32k]
  ------------------
 1209|      0|         return if_match(req, "RSA/PKCS1v15(SHA-384)", {1, 2, 840, 113549, 1, 1, 12});
 1210|      0|      case 0x84596:
  ------------------
  |  Branch (1210:7): [True: 0, False: 1.32k]
  ------------------
 1211|      0|         return if_match(req, "eFrodoKEM-640-AES", {1, 3, 6, 1, 4, 1, 25258, 1, 17, 1});
 1212|      0|      case 0x8469F:
  ------------------
  |  Branch (1212:7): [True: 0, False: 1.32k]
  ------------------
 1213|      0|         return if_match(req, "ClassicMcEliece_6960119pcf", {1, 3, 6, 1, 4, 1, 25258, 1, 18, 4});
 1214|      0|      case 0x84CA4:
  ------------------
  |  Branch (1214:7): [True: 0, False: 1.32k]
  ------------------
 1215|      0|         return if_match(req, "secp256k1", {1, 3, 132, 0, 10});
 1216|      0|      case 0x85381:
  ------------------
  |  Branch (1216:7): [True: 0, False: 1.32k]
  ------------------
 1217|      0|         return if_match(req, "secp256r1", {1, 2, 840, 10045, 3, 1, 7});
 1218|      0|      case 0x854FC:
  ------------------
  |  Branch (1218:7): [True: 0, False: 1.32k]
  ------------------
 1219|      0|         return if_match(req, "PKIX.IPsecUser", {1, 3, 6, 1, 5, 5, 7, 3, 7});
 1220|      0|      case 0x85F51:
  ------------------
  |  Branch (1220:7): [True: 0, False: 1.32k]
  ------------------
 1221|      0|         return if_match(req, "Serpent/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 4});
 1222|      0|      case 0x862D9:
  ------------------
  |  Branch (1222:7): [True: 0, False: 1.32k]
  ------------------
 1223|      0|         return if_match(req, "ECGDSA/SHA-512", {1, 3, 36, 3, 3, 2, 5, 4, 6});
 1224|      0|      case 0x87585:
  ------------------
  |  Branch (1224:7): [True: 0, False: 1.32k]
  ------------------
 1225|      0|         return if_match(req, "Twofish/CBC", {1, 3, 6, 1, 4, 1, 25258, 3, 3});
 1226|      0|      case 0x877D1:
  ------------------
  |  Branch (1226:7): [True: 0, False: 1.32k]
  ------------------
 1227|      0|         return if_match(req, "PKCS9.EmailAddress", {1, 2, 840, 113549, 1, 9, 1});
 1228|      0|      case 0x87D27:
  ------------------
  |  Branch (1228:7): [True: 0, False: 1.32k]
  ------------------
 1229|      0|         return if_match(req, "PKIX.CertificateAuthorityIssuers", {1, 3, 6, 1, 5, 5, 7, 48, 2});
 1230|      0|      case 0x87E42:
  ------------------
  |  Branch (1230:7): [True: 0, False: 1.32k]
  ------------------
 1231|      0|         return if_match(req, "X509v3.AuthorityKeyIdentifier", {2, 5, 29, 35});
 1232|      0|      case 0x889B1:
  ------------------
  |  Branch (1232:7): [True: 0, False: 1.32k]
  ------------------
 1233|      0|         return if_match(req, "ECDSA/SHA-1", {1, 2, 840, 10045, 4, 1});
 1234|      0|      case 0x89658:
  ------------------
  |  Branch (1234:7): [True: 0, False: 1.32k]
  ------------------
 1235|      0|         return if_match(req, "PBE-PKCS5v20", {1, 2, 840, 113549, 1, 5, 13});
 1236|      0|      case 0x8976D:
  ------------------
  |  Branch (1236:7): [True: 0, False: 1.32k]
  ------------------
 1237|      0|         return if_match(req, "PKCS9.MessageDigest", {1, 2, 840, 113549, 1, 9, 4});
 1238|      0|      case 0x8B002:
  ------------------
  |  Branch (1238:7): [True: 0, False: 1.32k]
  ------------------
 1239|      0|         return if_match(req, "Camellia-256/OCB", {1, 3, 6, 1, 4, 1, 25258, 3, 2, 8});
 1240|      0|      case 0x8B935:
  ------------------
  |  Branch (1240:7): [True: 0, False: 1.32k]
  ------------------
 1241|      0|         return if_match(req, "ClassicMcEliece_6688128", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 5});
 1242|      0|      case 0x8BB11:
  ------------------
  |  Branch (1242:7): [True: 0, False: 1.32k]
  ------------------
 1243|      0|         return if_match(req, "X509v3.NoRevocationAvailable", {2, 5, 29, 56});
 1244|      0|      case 0x8CE3D:
  ------------------
  |  Branch (1244:7): [True: 0, False: 1.32k]
  ------------------
 1245|      0|         return if_match(req, "PKCS9.ChallengePassword", {1, 2, 840, 113549, 1, 9, 7});
 1246|      0|      case 0x8D45C:
  ------------------
  |  Branch (1246:7): [True: 0, False: 1.32k]
  ------------------
 1247|      0|         return if_match(req, "ECKCDSA", {1, 0, 14888, 3, 0, 5});
 1248|      0|      case 0x8E0C1:
  ------------------
  |  Branch (1248:7): [True: 0, False: 1.32k]
  ------------------
 1249|      0|         return if_match(req, "X509v3.CertificatePolicies", {2, 5, 29, 32});
 1250|      0|      case 0x8E39A:
  ------------------
  |  Branch (1250:7): [True: 0, False: 1.32k]
  ------------------
 1251|      0|         return if_match(req, "HSS-LMS-Private-Key", {1, 3, 6, 1, 4, 1, 25258, 1, 13});
 1252|      0|      case 0x8EC51:
  ------------------
  |  Branch (1252:7): [True: 0, False: 1.32k]
  ------------------
 1253|      0|         return if_match(req, "Kyber-768-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 7, 2});
 1254|      0|      case 0x8F94A:
  ------------------
  |  Branch (1254:7): [True: 0, False: 1.32k]
  ------------------
 1255|      0|         return if_match(req, "Dilithium-6x5-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 9, 2});
 1256|      0|      case 0x8FC20:
  ------------------
  |  Branch (1256:7): [True: 0, False: 1.32k]
  ------------------
 1257|      0|         return if_match(req, "AES-128/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 1});
 1258|      0|      case 0x8FDE0:
  ------------------
  |  Branch (1258:7): [True: 0, False: 1.32k]
  ------------------
 1259|      0|         return if_match(req, "SHA-3(256)", {2, 16, 840, 1, 101, 3, 4, 2, 8});
 1260|      0|      case 0x919E3:
  ------------------
  |  Branch (1260:7): [True: 0, False: 1.32k]
  ------------------
 1261|      0|         return if_match(req, "Serpent/GCM", {1, 3, 6, 1, 4, 1, 25258, 3, 101});
 1262|      0|      case 0x91C1A:
  ------------------
  |  Branch (1262:7): [True: 0, False: 1.32k]
  ------------------
 1263|      0|         return if_match(req, "X25519", {1, 3, 101, 110});
 1264|      0|      case 0x91DC4:
  ------------------
  |  Branch (1264:7): [True: 0, False: 1.32k]
  ------------------
 1265|      0|         return if_match(req, "McEliece", {1, 3, 6, 1, 4, 1, 25258, 1, 3});
 1266|      0|      case 0x93467:
  ------------------
  |  Branch (1266:7): [True: 0, False: 1.32k]
  ------------------
 1267|      0|         return if_match(req, "Dilithium-6x5-AES-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 10, 2});
 1268|      0|      case 0x93D50:
  ------------------
  |  Branch (1268:7): [True: 0, False: 1.32k]
  ------------------
 1269|      0|         return if_match(req, "AES-192/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 2});
 1270|      0|      case 0x95166:
  ------------------
  |  Branch (1270:7): [True: 0, False: 1.32k]
  ------------------
 1271|      0|         return if_match(req, "SLH-DSA-SHAKE-128f", {2, 16, 840, 1, 101, 3, 4, 3, 27});
 1272|      0|      case 0x95173:
  ------------------
  |  Branch (1272:7): [True: 0, False: 1.32k]
  ------------------
 1273|      0|         return if_match(req, "SLH-DSA-SHAKE-128s", {2, 16, 840, 1, 101, 3, 4, 3, 26});
 1274|      0|      case 0x952D6:
  ------------------
  |  Branch (1274:7): [True: 0, False: 1.32k]
  ------------------
 1275|      0|         return if_match(req, "PKIX.OCSP", {1, 3, 6, 1, 5, 5, 7, 48, 1});
 1276|      0|      case 0x959B9:
  ------------------
  |  Branch (1276:7): [True: 0, False: 1.32k]
  ------------------
 1277|      0|         return if_match(req, "PKIX.IPsecEndSystem", {1, 3, 6, 1, 5, 5, 7, 3, 5});
 1278|      0|      case 0x96F85:
  ------------------
  |  Branch (1278:7): [True: 0, False: 1.32k]
  ------------------
 1279|      0|         return if_match(req, "Camellia-256/CBC", {1, 2, 392, 200011, 61, 1, 1, 1, 4});
 1280|      0|      case 0x97D5E:
  ------------------
  |  Branch (1280:7): [True: 0, False: 1.32k]
  ------------------
 1281|      0|         return if_match(req, "HMAC(SHA-1)", {1, 2, 840, 113549, 2, 7});
 1282|      0|      case 0x9805C:
  ------------------
  |  Branch (1282:7): [True: 0, False: 1.32k]
  ------------------
 1283|      0|         return if_match(req, "SEED/CBC", {1, 2, 410, 200004, 1, 4});
 1284|      0|      case 0x980E7:
  ------------------
  |  Branch (1284:7): [True: 0, False: 1.32k]
  ------------------
 1285|      0|         return if_match(req, "SphincsPlus-haraka-192s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 3});
 1286|      0|      case 0x980F5:
  ------------------
  |  Branch (1286:7): [True: 0, False: 1.32k]
  ------------------
 1287|      0|         return if_match(req, "GOST.SubjectSigningTool", {1, 2, 643, 100, 111});
 1288|      0|      case 0x98B03:
  ------------------
  |  Branch (1288:7): [True: 0, False: 1.32k]
  ------------------
 1289|      0|         return if_match(req, "XMSS", {0, 4, 0, 127, 0, 15, 1, 1, 13, 0});
 1290|      0|      case 0x9A6B2:
  ------------------
  |  Branch (1290:7): [True: 0, False: 1.32k]
  ------------------
 1291|      0|         return if_match(req, "ECKCDSA/SHA-1", {1, 2, 410, 200004, 1, 100, 4, 3});
 1292|      0|      case 0x9B1CF:
  ------------------
  |  Branch (1292:7): [True: 0, False: 1.32k]
  ------------------
 1293|      0|         return if_match(req, "SM4/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 9});
 1294|      0|      case 0x9B6B2:
  ------------------
  |  Branch (1294:7): [True: 0, False: 1.32k]
  ------------------
 1295|      0|         return if_match(req, "AES-128/GCM", {2, 16, 840, 1, 101, 3, 4, 1, 6});
 1296|      0|      case 0x9B6BB:
  ------------------
  |  Branch (1296:7): [True: 0, False: 1.32k]
  ------------------
 1297|      0|         return if_match(req, "X520.OrganizationalUnit", {2, 5, 4, 11});
 1298|      0|      case 0x9B851:
  ------------------
  |  Branch (1298:7): [True: 0, False: 1.32k]
  ------------------
 1299|      0|         return if_match(req, "OpenPGP.Curve25519", {1, 3, 6, 1, 4, 1, 3029, 1, 5, 1});
 1300|      0|      case 0x9C80B:
  ------------------
  |  Branch (1300:7): [True: 0, False: 1.32k]
  ------------------
 1301|      0|         return if_match(req, "SLH-DSA-SHA2-192f", {2, 16, 840, 1, 101, 3, 4, 3, 23});
 1302|      0|      case 0x9C818:
  ------------------
  |  Branch (1302:7): [True: 0, False: 1.32k]
  ------------------
 1303|      0|         return if_match(req, "SLH-DSA-SHA2-192s", {2, 16, 840, 1, 101, 3, 4, 3, 22});
 1304|      0|      case 0x9CD2B:
  ------------------
  |  Branch (1304:7): [True: 0, False: 1.32k]
  ------------------
 1305|      0|         return if_match(req, "Scrypt", {1, 3, 6, 1, 4, 1, 11591, 4, 11});
 1306|      0|      case 0x9CDE1:
  ------------------
  |  Branch (1306:7): [True: 0, False: 1.32k]
  ------------------
 1307|      0|         return if_match(req, "GOST-34.10-2012-256/SHA-256", {1, 3, 6, 1, 4, 1, 25258, 1, 6, 1});
 1308|      0|      case 0x9CF73:
  ------------------
  |  Branch (1308:7): [True: 0, False: 1.32k]
  ------------------
 1309|      0|         return if_match(req, "ClassicMcEliece_460896f", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 4});
 1310|      0|      case 0x9D354:
  ------------------
  |  Branch (1310:7): [True: 0, False: 1.32k]
  ------------------
 1311|      0|         return if_match(req, "RIPEMD-160", {1, 3, 36, 3, 2, 1});
 1312|      0|      case 0x9D503:
  ------------------
  |  Branch (1312:7): [True: 0, False: 1.32k]
  ------------------
 1313|      0|         return if_match(req, "RSA/PKCS1v15(SHA-256)", {1, 2, 840, 113549, 1, 1, 11});
 1314|      0|      case 0x9EC88:
  ------------------
  |  Branch (1314:7): [True: 0, False: 1.32k]
  ------------------
 1315|      0|         return if_match(req, "DSA/SHA-3(512)", {2, 16, 840, 1, 101, 3, 4, 3, 8});
 1316|      0|      case 0x9EF36:
  ------------------
  |  Branch (1316:7): [True: 0, False: 1.32k]
  ------------------
 1317|      0|         return if_match(req, "ClassicMcEliece_6960119", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 7});
 1318|      0|      case 0x9F764:
  ------------------
  |  Branch (1318:7): [True: 0, False: 1.32k]
  ------------------
 1319|      0|         return if_match(req, "X448", {1, 3, 101, 111});
 1320|      0|      case 0x9F7E2:
  ------------------
  |  Branch (1320:7): [True: 0, False: 1.32k]
  ------------------
 1321|      0|         return if_match(req, "AES-192/GCM", {2, 16, 840, 1, 101, 3, 4, 1, 26});
 1322|      0|      case 0x9F9C5:
  ------------------
  |  Branch (1322:7): [True: 0, False: 1.32k]
  ------------------
 1323|      0|         return if_match(req, "ClassicMcEliece_6688128pcf", {1, 3, 6, 1, 4, 1, 25258, 1, 18, 2});
 1324|      0|      case 0xA0805:
  ------------------
  |  Branch (1324:7): [True: 0, False: 1.32k]
  ------------------
 1325|      0|         return if_match(req, "PKCS9.SDSICertificate", {1, 2, 840, 113549, 1, 9, 22, 2});
 1326|      0|      case 0xA2B5B:
  ------------------
  |  Branch (1326:7): [True: 0, False: 1.32k]
  ------------------
 1327|      0|         return if_match(req, "X509v3.CRLNumber", {2, 5, 29, 20});
 1328|      0|      case 0xA3005:
  ------------------
  |  Branch (1328:7): [True: 0, False: 1.32k]
  ------------------
 1329|      0|         return if_match(req, "X520.Title", {2, 5, 4, 12});
 1330|      0|      case 0xA323F:
  ------------------
  |  Branch (1330:7): [True: 0, False: 1.32k]
  ------------------
 1331|      0|         return if_match(req, "X509v3.NameConstraints", {2, 5, 29, 30});
 1332|      0|      case 0xA3C55:
  ------------------
  |  Branch (1332:7): [True: 0, False: 1.32k]
  ------------------
 1333|      0|         return if_match(req, "X520.Pseudonym", {2, 5, 4, 65});
 1334|      0|      case 0xA4809:
  ------------------
  |  Branch (1334:7): [True: 0, False: 1.32k]
  ------------------
 1335|      0|         return if_match(req, "SphincsPlus-sha2-256f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 6});
 1336|      0|      case 0xA57AF:
  ------------------
  |  Branch (1336:7): [True: 0, False: 1.32k]
  ------------------
 1337|      0|         return if_match(req, "secp521r1", {1, 3, 132, 0, 35});
 1338|      0|      case 0xA5DA9:
  ------------------
  |  Branch (1338:7): [True: 0, False: 1.32k]
  ------------------
 1339|      0|         return if_match(req, "SphincsPlus-shake-256f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 6});
 1340|      0|      case 0xA6865:
  ------------------
  |  Branch (1340:7): [True: 0, False: 1.32k]
  ------------------
 1341|      0|         return if_match(req, "Camellia-128/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 6});
 1342|      0|      case 0xA6C61:
  ------------------
  |  Branch (1342:7): [True: 0, False: 1.32k]
  ------------------
 1343|      0|         return if_match(req, "SM4/GCM", {1, 2, 156, 10197, 1, 104, 8});
 1344|      0|      case 0xA8439:
  ------------------
  |  Branch (1344:7): [True: 0, False: 1.32k]
  ------------------
 1345|      0|         return if_match(req, "PKCS12.CertBag", {1, 2, 840, 113549, 1, 12, 10, 1, 3});
 1346|      0|      case 0xA9061:
  ------------------
  |  Branch (1346:7): [True: 0, False: 1.32k]
  ------------------
 1347|      0|         return if_match(req, "Kyber-768-90s-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 11, 2});
 1348|      0|      case 0xAA995:
  ------------------
  |  Branch (1348:7): [True: 0, False: 1.32k]
  ------------------
 1349|      0|         return if_match(req, "Camellia-192/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 7});
 1350|      0|      case 0xAAE2B:
  ------------------
  |  Branch (1350:7): [True: 0, False: 1.32k]
  ------------------
 1351|      0|         return if_match(req, "Dilithium-8x7-AES-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 10, 3});
 1352|      0|      case 0xABCED:
  ------------------
  |  Branch (1352:7): [True: 0, False: 1.32k]
  ------------------
 1353|      0|         return if_match(req, "GOST.IssuerSigningTool", {1, 2, 643, 100, 112});
 1354|      0|      case 0xABD24:
  ------------------
  |  Branch (1354:7): [True: 0, False: 1.32k]
  ------------------
 1355|      0|         return if_match(req, "RSA/OAEP", {1, 2, 840, 113549, 1, 1, 7});
 1356|      0|      case 0xAC2EC:
  ------------------
  |  Branch (1356:7): [True: 0, False: 1.32k]
  ------------------
 1357|      0|         return if_match(req, "Streebog-256", {1, 2, 643, 7, 1, 1, 2, 2});
 1358|      0|      case 0xAC3DD:
  ------------------
  |  Branch (1358:7): [True: 0, False: 1.32k]
  ------------------
 1359|      0|         return if_match(req, "Certificate Comment", {2, 16, 840, 1, 113730, 1, 13});
 1360|      0|      case 0xAC511:
  ------------------
  |  Branch (1360:7): [True: 0, False: 1.32k]
  ------------------
 1361|      0|         return if_match(req, "PBE-SHA1-3DES", {1, 2, 840, 113549, 1, 12, 1, 3});
 1362|      0|      case 0xAE6FE:
  ------------------
  |  Branch (1362:7): [True: 0, False: 1.32k]
  ------------------
 1363|      0|         return if_match(req, "PKIX.ClientAuth", {1, 3, 6, 1, 5, 5, 7, 3, 2});
 1364|      0|      case 0xAE8D3:
  ------------------
  |  Branch (1364:7): [True: 0, False: 1.32k]
  ------------------
 1365|      0|         return if_match(req, "ClassicMcEliece_8192128pcf", {1, 3, 6, 1, 4, 1, 25258, 1, 18, 6});
 1366|      0|      case 0xAF476:
  ------------------
  |  Branch (1366:7): [True: 0, False: 1.32k]
  ------------------
 1367|      0|         return if_match(req, "ECDH", {1, 3, 132, 1, 12});
 1368|      0|      case 0xAFA6A:
  ------------------
  |  Branch (1368:7): [True: 0, False: 1.32k]
  ------------------
 1369|      0|         return if_match(req, "RSA/PKCS1v15(SHA-3(384))", {2, 16, 840, 1, 101, 3, 4, 3, 15});
 1370|      0|      case 0xB2217:
  ------------------
  |  Branch (1370:7): [True: 0, False: 1.32k]
  ------------------
 1371|      0|         return if_match(req, "AES-256/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 3});
 1372|      0|      case 0xB22F7:
  ------------------
  |  Branch (1372:7): [True: 0, False: 1.32k]
  ------------------
 1373|      0|         return if_match(req, "Camellia-128/GCM", {0, 3, 4401, 5, 3, 1, 9, 6});
 1374|      0|      case 0xB23DE:
  ------------------
  |  Branch (1374:7): [True: 0, False: 1.32k]
  ------------------
 1375|      0|         return if_match(req, "X520.Locality", {2, 5, 4, 7});
 1376|      0|      case 0xB2FBD:
  ------------------
  |  Branch (1376:7): [True: 0, False: 1.32k]
  ------------------
 1377|      0|         return if_match(req, "ECKCDSA/SHA-224", {1, 2, 410, 200004, 1, 100, 4, 4});
 1378|      0|      case 0xB32B0:
  ------------------
  |  Branch (1378:7): [True: 0, False: 1.32k]
  ------------------
 1379|      0|         return if_match(req, "ECKCDSA/SHA-256", {1, 2, 410, 200004, 1, 100, 4, 5});
 1380|      0|      case 0xB360E:
  ------------------
  |  Branch (1380:7): [True: 0, False: 1.32k]
  ------------------
 1381|      0|         return if_match(req, "eFrodoKEM-976-SHAKE", {1, 3, 6, 1, 4, 1, 25258, 1, 16, 2});
 1382|      0|      case 0xB4368:
  ------------------
  |  Branch (1382:7): [True: 0, False: 1.32k]
  ------------------
 1383|      0|         return if_match(req, "ECGDSA/SHA-1", {1, 3, 36, 3, 3, 2, 5, 4, 2});
 1384|      0|      case 0xB58CD:
  ------------------
  |  Branch (1384:7): [True: 0, False: 1.32k]
  ------------------
 1385|      0|         return if_match(req, "RSA/PKCS1v15(SHA-3(512))", {2, 16, 840, 1, 101, 3, 4, 3, 16});
 1386|      0|      case 0xB6427:
  ------------------
  |  Branch (1386:7): [True: 0, False: 1.32k]
  ------------------
 1387|      0|         return if_match(req, "Camellia-192/GCM", {0, 3, 4401, 5, 3, 1, 9, 26});
 1388|      0|      case 0xB7102:
  ------------------
  |  Branch (1388:7): [True: 0, False: 1.32k]
  ------------------
 1389|      0|         return if_match(req, "brainpool224r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 5});
 1390|      0|      case 0xB710D:
  ------------------
  |  Branch (1390:7): [True: 0, False: 1.32k]
  ------------------
 1391|      0|         return if_match(req, "X509v3.CRLIssuingDistributionPoint", {2, 5, 29, 28});
 1392|      0|      case 0xB72D4:
  ------------------
  |  Branch (1392:7): [True: 0, False: 1.32k]
  ------------------
 1393|      0|         return if_match(req, "Microsoft UPN", {1, 3, 6, 1, 4, 1, 311, 20, 2, 3});
 1394|      0|      case 0xB73A5:
  ------------------
  |  Branch (1394:7): [True: 0, False: 1.32k]
  ------------------
 1395|      0|         return if_match(req, "RSA/PSS", {1, 2, 840, 113549, 1, 1, 10});
 1396|      0|      case 0xB84B3:
  ------------------
  |  Branch (1396:7): [True: 0, False: 1.32k]
  ------------------
 1397|      0|         return if_match(req, "PKIX.CodeSigning", {1, 3, 6, 1, 5, 5, 7, 3, 3});
 1398|      0|      case 0xB8CB9:
  ------------------
  |  Branch (1398:7): [True: 0, False: 1.32k]
  ------------------
 1399|      0|         return if_match(req, "GOST-34.10-2012-256", {1, 2, 643, 7, 1, 1, 1, 1});
 1400|      0|      case 0xB945C:
  ------------------
  |  Branch (1400:7): [True: 0, False: 1.32k]
  ------------------
 1401|      0|         return if_match(req, "Twofish/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 5});
 1402|      0|      case 0xB94E4:
  ------------------
  |  Branch (1402:7): [True: 0, False: 1.32k]
  ------------------
 1403|      0|         return if_match(req, "gost_512A", {1, 2, 643, 7, 1, 2, 1, 2, 1});
 1404|      0|      case 0xB94E5:
  ------------------
  |  Branch (1404:7): [True: 0, False: 1.32k]
  ------------------
 1405|      0|         return if_match(req, "gost_512B", {1, 2, 643, 7, 1, 2, 1, 2, 2});
 1406|      0|      case 0xBA1D8:
  ------------------
  |  Branch (1406:7): [True: 0, False: 1.32k]
  ------------------
 1407|      0|         return if_match(req, "X520.StreetAddress", {2, 5, 4, 9});
 1408|      0|      case 0xBCB45:
  ------------------
  |  Branch (1408:7): [True: 0, False: 1.32k]
  ------------------
 1409|      0|         return if_match(req, "PKCS12.CRLBag", {1, 2, 840, 113549, 1, 12, 10, 1, 4});
 1410|      0|      case 0xBCC82:
  ------------------
  |  Branch (1410:7): [True: 0, False: 1.32k]
  ------------------
 1411|      0|         return if_match(req, "x962_p239v1", {1, 2, 840, 10045, 3, 1, 4});
 1412|      0|      case 0xBCC83:
  ------------------
  |  Branch (1412:7): [True: 0, False: 1.32k]
  ------------------
 1413|      0|         return if_match(req, "x962_p239v2", {1, 2, 840, 10045, 3, 1, 5});
 1414|      0|      case 0xBCC84:
  ------------------
  |  Branch (1414:7): [True: 0, False: 1.32k]
  ------------------
 1415|      0|         return if_match(req, "x962_p239v3", {1, 2, 840, 10045, 3, 1, 6});
 1416|      0|      case 0xBD92B:
  ------------------
  |  Branch (1416:7): [True: 0, False: 1.32k]
  ------------------
 1417|      0|         return if_match(req, "X509v3.HoldInstructionCode", {2, 5, 29, 23});
 1418|      0|      case 0xBDCA9:
  ------------------
  |  Branch (1418:7): [True: 0, False: 1.32k]
  ------------------
 1419|      0|         return if_match(req, "AES-256/GCM", {2, 16, 840, 1, 101, 3, 4, 1, 46});
 1420|      0|      case 0xBE48D:
  ------------------
  |  Branch (1420:7): [True: 0, False: 1.32k]
  ------------------
 1421|      0|         return if_match(req, "PKIX.OCSP.BasicResponse", {1, 3, 6, 1, 5, 5, 7, 48, 1, 1});
 1422|      0|      case 0xBF71E:
  ------------------
  |  Branch (1422:7): [True: 0, False: 1.32k]
  ------------------
 1423|      0|         return if_match(req, "Kyber-1024-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 7, 3});
 1424|      0|      case 0xBFF01:
  ------------------
  |  Branch (1424:7): [True: 0, False: 1.32k]
  ------------------
 1425|      0|         return if_match(req, "DSA/SHA-3(224)", {2, 16, 840, 1, 101, 3, 4, 3, 5});
 1426|      0|      case 0xC0F4F:
  ------------------
  |  Branch (1426:7): [True: 0, False: 1.32k]
  ------------------
 1427|      0|         return if_match(req, "SphincsPlus-haraka-256f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 6});
 1428|      0|      case 0xC1875:
  ------------------
  |  Branch (1428:7): [True: 0, False: 1.32k]
  ------------------
 1429|      0|         return if_match(req, "SHA-1", {1, 3, 14, 3, 2, 26});
 1430|      0|      case 0xC28D1:
  ------------------
  |  Branch (1430:7): [True: 0, False: 1.32k]
  ------------------
 1431|      0|         return if_match(req, "PKIX.OCSPSigning", {1, 3, 6, 1, 5, 5, 7, 3, 9});
 1432|      0|      case 0xC42CA:
  ------------------
  |  Branch (1432:7): [True: 0, False: 1.32k]
  ------------------
 1433|      0|         return if_match(req, "brainpool256r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 7});
 1434|      0|      default:
  ------------------
  |  Branch (1434:7): [True: 0, False: 1.32k]
  ------------------
 1435|      0|         return {};
 1436|  1.32k|   }
 1437|  1.32k|}
_ZN5Botan7OID_Map16load_oid2str_mapEv:
 1439|      1|std::unordered_map<OID, std::string> OID_Map::load_oid2str_map() {
 1440|      1|   return {
 1441|      1|      {OID{2, 5, 8, 1, 1}, "RSA"},
 1442|      1|      {OID{1, 3, 6, 1, 4, 1, 8301, 3, 1, 2, 9, 0, 38}, "secp521r1"},
 1443|      1|      {OID{1, 2, 643, 2, 2, 35, 1}, "gost_256A"},
 1444|      1|      {OID{1, 2, 643, 2, 2, 36, 0}, "gost_256A"},
 1445|      1|   };
 1446|      1|}
_ZN5Botan7OID_Map16load_str2oid_mapEv:
 1448|      1|std::unordered_map<std::string, OID> OID_Map::load_str2oid_map() {
 1449|      1|   return {
 1450|      1|      {"Curve25519", OID{1, 3, 101, 110}},
 1451|      1|      {"SM2_Sig", OID{1, 2, 156, 10197, 1, 301, 1}},
 1452|      1|      {"RSA/EMSA3(MD2)", OID{1, 2, 840, 113549, 1, 1, 2}},
 1453|      1|      {"RSA/EMSA3(MD5)", OID{1, 2, 840, 113549, 1, 1, 4}},
 1454|      1|      {"RSA/EMSA3(SHA-1)", OID{1, 2, 840, 113549, 1, 1, 5}},
 1455|      1|      {"RSA/EMSA3(SHA-256)", OID{1, 2, 840, 113549, 1, 1, 11}},
 1456|      1|      {"RSA/EMSA3(SHA-384)", OID{1, 2, 840, 113549, 1, 1, 12}},
 1457|      1|      {"RSA/EMSA3(SHA-512)", OID{1, 2, 840, 113549, 1, 1, 13}},
 1458|      1|      {"RSA/EMSA3(SHA-224)", OID{1, 2, 840, 113549, 1, 1, 14}},
 1459|      1|      {"RSA/EMSA3(SHA-512-256)", OID{1, 2, 840, 113549, 1, 1, 16}},
 1460|      1|      {"RSA/EMSA3(SHA-3(224))", OID{2, 16, 840, 1, 101, 3, 4, 3, 13}},
 1461|      1|      {"RSA/EMSA3(SHA-3(256))", OID{2, 16, 840, 1, 101, 3, 4, 3, 14}},
 1462|      1|      {"RSA/EMSA3(SHA-3(384))", OID{2, 16, 840, 1, 101, 3, 4, 3, 15}},
 1463|      1|      {"RSA/EMSA3(SHA-3(512))", OID{2, 16, 840, 1, 101, 3, 4, 3, 16}},
 1464|      1|      {"RSA/EMSA3(SM3)", OID{1, 2, 156, 10197, 1, 504}},
 1465|      1|      {"RSA/EMSA3(RIPEMD-160)", OID{1, 3, 36, 3, 3, 1, 2}},
 1466|      1|      {"RSA/EMSA4", OID{1, 2, 840, 113549, 1, 1, 10}},
 1467|      1|      {"PBES2", OID{1, 2, 840, 113549, 1, 5, 13}},
 1468|      1|   };
 1469|      1|}
static_oids.cpp:_ZN5Botan12_GLOBAL__N_18if_matchERKNS_3OIDESt16initializer_listIjENSt3__117basic_string_viewIcNS6_11char_traitsIcEEEE:
   18|    342|std::optional<std::string_view> if_match(const OID& oid, std::initializer_list<uint32_t> val, std::string_view name) {
   19|    342|   if(oid.matches(val)) {
  ------------------
  |  Branch (19:7): [True: 0, False: 342]
  ------------------
   20|      0|      return name;
   21|    342|   } else {
   22|    342|      return {};
   23|    342|   }
   24|    342|}
static_oids.cpp:_ZN5Botan12_GLOBAL__N_113hash_oid_nameENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   34|  1.32k|uint32_t hash_oid_name(std::string_view s) {
   35|  1.32k|   uint64_t hash = 0x8188B31879A4879A;
   36|       |
   37|  38.3k|   for(const char c : s) {
  ------------------
  |  Branch (37:21): [True: 38.3k, False: 1.32k]
  ------------------
   38|  38.3k|      hash *= 251;
   39|  38.3k|      hash += c;
   40|  38.3k|   }
   41|       |
   42|  1.32k|   return static_cast<uint32_t>(hash % 805289);
   43|  1.32k|}
static_oids.cpp:_ZN5Botan12_GLOBAL__N_18if_matchENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_St16initializer_listIjE:
   26|  1.32k|std::optional<OID> if_match(std::string_view req, std::string_view actual, std::initializer_list<uint32_t> oid) {
   27|  1.32k|   if(req == actual) {
  ------------------
  |  Branch (27:7): [True: 1.32k, False: 0]
  ------------------
   28|  1.32k|      return OID(oid);
   29|  1.32k|   } else {
   30|      0|      return {};
   31|      0|   }
   32|  1.32k|}

_ZN5Botan20Buffered_Computation5finalENSt3__14spanIhLm18446744073709551615EEE:
   54|  6.60k|void Buffered_Computation::final(std::span<uint8_t> out) {
   55|  6.60k|   BOTAN_ARG_CHECK(out.size() >= output_length(), "Output buffer has insufficient capacity");
  ------------------
  |  |   35|  6.60k|   do {                                                          \
  |  |   36|  6.60k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  6.60k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 6.60k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  6.60k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 6.60k]
  |  |  ------------------
  ------------------
   56|       |   // Pass exactly output_length() bytes so that an oversized buffer has the
   57|       |   // result written to its leading bytes with the remainder left untouched.
   58|  6.60k|   final_result(out.first(output_length()));
   59|  6.60k|}

_ZN5Botan13base64_decodeEPKcmb:
  189|     92|secure_vector<uint8_t> base64_decode(const char input[], size_t input_length, bool ignore_ws) {
  190|     92|   return base_decode_to_vec<secure_vector<uint8_t>>(Base64(), input, input_length, ignore_ws);
  191|     92|}
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base6417decode_max_outputEm:
   43|    184|      static constexpr size_t decode_max_output(size_t input_length) {
   44|       |         // Divide before multiply to avoid overflow; round_up makes the division exact.
   45|    184|         return (round_up(input_length, m_encoding_bytes_out) / m_encoding_bytes_out) * m_encoding_bytes_in;
   46|    184|      }
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base6413bits_consumedEv:
   34|     22|      static constexpr size_t bits_consumed() noexcept { return m_encoding_bits; }
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base6419lookup_binary_valueEc:
  112|  3.37k|uint8_t Base64::lookup_binary_value(char input) noexcept {
  113|  3.37k|   auto has_zero_byte = [](uint64_t v) { return ((v - 0x0101010101010101) & ~(v) & 0x8080808080808080); };
  114|       |
  115|       |   // Assumes each byte is either 0x00 or 0x80
  116|  3.37k|   auto index_of_first_set_byte = [](uint64_t v) {
  117|  3.37k|      return ((((v - 1) & 0x0101010101010101) * 0x0101010101010101) >> 56) - 1;
  118|  3.37k|   };
  119|       |
  120|  3.37k|   constexpr uint64_t lo = 0x0101010101010101;
  121|       |
  122|  3.37k|   const uint8_t x = static_cast<uint8_t>(input);
  123|       |
  124|  3.37k|   const uint64_t x8 = x * lo;
  125|       |
  126|       |   // Defines the valid ASCII ranges of base64, except the special chars (below)
  127|  3.37k|   constexpr uint64_t val_l = make_uint64(0, 0, 0, 0, 0, 'A', 'a', '0');
  128|  3.37k|   constexpr uint64_t val_u = make_uint64(0, 0, 0, 0, 0, 26, 26, 10);
  129|       |
  130|       |   // If x is in one of the ranges return a mask. Otherwise we xor in at the
  131|       |   // high word which will be our invalid marker
  132|  3.37k|   auto v_mask = swar_in_range<uint64_t>(x8, val_l, val_u) ^ 0x80000000;
  133|       |
  134|       |   // This is the offset added to x to get the value
  135|  3.37k|   const uint64_t val_v = 0xbfb904 ^ (0xFF000000 - (x << 24));
  136|       |
  137|  3.37k|   const uint8_t z = x + static_cast<uint8_t>(val_v >> (8 * index_of_first_set_byte(v_mask)));
  138|       |
  139|       |   // Valid base64 special characters, and some whitespace chars
  140|  3.37k|   constexpr uint64_t specials_i = make_uint64(0, '+', '/', '=', ' ', '\n', '\t', '\r');
  141|       |
  142|  3.37k|   const uint64_t specials_v = 0x3e3f8180808080 ^ (static_cast<uint64_t>(z) << 56);
  143|       |
  144|  3.37k|   const uint64_t smask = has_zero_byte(x8 ^ specials_i) ^ 0x8000000000000000;
  145|       |
  146|  3.37k|   return static_cast<uint8_t>(specials_v >> (8 * index_of_first_set_byte(smask)));
  147|  3.37k|}
base64.cpp:_ZZN5Botan12_GLOBAL__N_16Base6419lookup_binary_valueEcENK3$_0clEm:
  116|  6.74k|   auto index_of_first_set_byte = [](uint64_t v) {
  117|  6.74k|      return ((((v - 1) & 0x0101010101010101) * 0x0101010101010101) >> 56) - 1;
  118|  6.74k|   };
base64.cpp:_ZZN5Botan12_GLOBAL__N_16Base6419lookup_binary_valueEcENK3$_1clEm:
  113|  3.37k|   auto has_zero_byte = [](uint64_t v) { return ((v - 0x0101010101010101) & ~(v) & 0x8080808080808080); };
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base6414check_bad_charEhcb:
  150|  3.08k|bool Base64::check_bad_char(uint8_t bin, char input, bool ignore_ws) {
  151|  3.08k|   if(bin <= 0x3F) {
  ------------------
  |  Branch (151:7): [True: 1.55k, False: 1.53k]
  ------------------
  152|  1.55k|      return true;
  153|  1.55k|   } else if(!(bin == 0x81 || (bin == 0x80 && ignore_ws))) {
  ------------------
  |  Branch (153:16): [True: 259, False: 1.27k]
  |  Branch (153:32): [True: 1.23k, False: 36]
  |  Branch (153:47): [True: 1.23k, False: 0]
  ------------------
  154|     36|      throw Invalid_Argument(fmt("base64_decode: invalid character '{}'", format_char_for_display(input)));
  155|     36|   }
  156|  1.49k|   return false;
  157|  3.08k|}
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base644nameEv:
   24|     19|      static std::string name() { return "base64"; }
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base646decodeEPhPKh:
   54|    376|      static void decode(uint8_t* out_ptr, const uint8_t decode_buf[4]) {
   55|    376|         out_ptr[0] = (decode_buf[0] << 2) | (decode_buf[1] >> 4);
   56|    376|         out_ptr[1] = (decode_buf[1] << 4) | (decode_buf[2] >> 2);
   57|    376|         out_ptr[2] = (decode_buf[2] << 6) | decode_buf[3];
   58|    376|      }
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base6415bytes_to_removeEm:
   60|     44|      static size_t bytes_to_remove(size_t final_truncate) { return final_truncate; }

_ZN5Botan10hex_encodeEPcPKhmb:
   34|  2.64k|void hex_encode(char output[], const uint8_t input[], size_t input_length, bool uppercase) {
   35|  71.3k|   for(size_t i = 0; i != input_length; ++i) {
  ------------------
  |  Branch (35:22): [True: 68.6k, False: 2.64k]
  ------------------
   36|  68.6k|      const uint16_t h = hex_encode_2nibble(input[i], uppercase);
   37|  68.6k|      output[2 * i] = get_byte<0>(h);
   38|  68.6k|      output[2 * i + 1] = get_byte<1>(h);
   39|  68.6k|   }
   40|  2.64k|}
_ZN5Botan10hex_encodeEPKhmb:
   42|  2.64k|std::string hex_encode(const uint8_t input[], size_t input_length, bool uppercase) {
   43|  2.64k|   const size_t output_length = mul_or_throw<size_t>(2, input_length, "Input too large to hex encode");
   44|  2.64k|   std::string output(output_length, 0);
   45|       |
   46|  2.64k|   if(input_length > 0) {
  ------------------
  |  Branch (46:7): [True: 2.64k, False: 0]
  ------------------
   47|  2.64k|      hex_encode(&output.front(), input, input_length, uppercase);
   48|  2.64k|   }
   49|       |
   50|  2.64k|   return output;
   51|  2.64k|}
hex.cpp:_ZN5Botan12_GLOBAL__N_118hex_encode_2nibbleEhb:
   21|  68.6k|uint16_t hex_encode_2nibble(uint8_t n8, bool uppercase) {
   22|       |   // Offset for upper or lower case 'a' resp
   23|  68.6k|   const uint16_t a_mask = uppercase ? 0x0707 : 0x2727;
  ------------------
  |  Branch (23:28): [True: 68.6k, False: 0]
  ------------------
   24|       |
   25|  68.6k|   const uint16_t n = (static_cast<uint16_t>(n8 & 0xF0) << 4) | (n8 & 0x0F);
   26|       |   // n >= 10? If so add offset
   27|  68.6k|   const uint16_t diff = swar_lt<uint16_t>(0x0909, n) & a_mask;
   28|       |   // Can't overflow between bytes, so don't need explicit SWAR addition:
   29|  68.6k|   return n + 0x3030 + diff;
   30|  68.6k|}

_ZN5Botan12HashFunction6createENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_:
  111|  11.7k|std::unique_ptr<HashFunction> HashFunction::create(std::string_view algo_spec, std::string_view provider) {
  112|       |#if defined(BOTAN_HAS_COMMONCRYPTO)
  113|       |   if(provider.empty() || provider == "commoncrypto") {
  114|       |      if(auto hash = make_commoncrypto_hash(algo_spec))
  115|       |         return hash;
  116|       |
  117|       |      if(!provider.empty())
  118|       |         return nullptr;
  119|       |   }
  120|       |#endif
  121|       |
  122|  11.7k|   if(provider.empty() == false && provider != "base") {
  ------------------
  |  Branch (122:7): [True: 0, False: 11.7k]
  |  Branch (122:36): [True: 0, False: 0]
  ------------------
  123|      0|      return nullptr;  // unknown provider
  124|      0|   }
  125|       |
  126|  11.7k|#if defined(BOTAN_HAS_SHA1)
  127|  11.7k|   if(algo_spec == "SHA-1") {
  ------------------
  |  Branch (127:7): [True: 1.32k, False: 10.4k]
  ------------------
  128|  1.32k|      return std::make_unique<SHA_1>();
  129|  1.32k|   }
  130|  10.4k|#endif
  131|       |
  132|  10.4k|#if defined(BOTAN_HAS_SHA2_32)
  133|  10.4k|   if(algo_spec == "SHA-224") {
  ------------------
  |  Branch (133:7): [True: 0, False: 10.4k]
  ------------------
  134|      0|      return std::make_unique<SHA_224>();
  135|      0|   }
  136|       |
  137|  10.4k|   if(algo_spec == "SHA-256") {
  ------------------
  |  Branch (137:7): [True: 10.4k, False: 0]
  ------------------
  138|  10.4k|      return std::make_unique<SHA_256>();
  139|  10.4k|   }
  140|      0|#endif
  141|       |
  142|      0|#if defined(BOTAN_HAS_SHA2_64)
  143|      0|   if(algo_spec == "SHA-384") {
  ------------------
  |  Branch (143:7): [True: 0, False: 0]
  ------------------
  144|      0|      return std::make_unique<SHA_384>();
  145|      0|   }
  146|       |
  147|      0|   if(algo_spec == "SHA-512") {
  ------------------
  |  Branch (147:7): [True: 0, False: 0]
  ------------------
  148|      0|      return std::make_unique<SHA_512>();
  149|      0|   }
  150|       |
  151|      0|   if(algo_spec == "SHA-512-256") {
  ------------------
  |  Branch (151:7): [True: 0, False: 0]
  ------------------
  152|      0|      return std::make_unique<SHA_512_256>();
  153|      0|   }
  154|      0|#endif
  155|       |
  156|      0|#if defined(BOTAN_HAS_RIPEMD_160)
  157|      0|   if(algo_spec == "RIPEMD-160") {
  ------------------
  |  Branch (157:7): [True: 0, False: 0]
  ------------------
  158|      0|      return std::make_unique<RIPEMD_160>();
  159|      0|   }
  160|      0|#endif
  161|       |
  162|      0|#if defined(BOTAN_HAS_WHIRLPOOL)
  163|      0|   if(algo_spec == "Whirlpool") {
  ------------------
  |  Branch (163:7): [True: 0, False: 0]
  ------------------
  164|      0|      return std::make_unique<Whirlpool>();
  165|      0|   }
  166|      0|#endif
  167|       |
  168|      0|#if defined(BOTAN_HAS_MD5)
  169|      0|   if(algo_spec == "MD5") {
  ------------------
  |  Branch (169:7): [True: 0, False: 0]
  ------------------
  170|      0|      return std::make_unique<MD5>();
  171|      0|   }
  172|      0|#endif
  173|       |
  174|      0|#if defined(BOTAN_HAS_MD4)
  175|      0|   if(algo_spec == "MD4") {
  ------------------
  |  Branch (175:7): [True: 0, False: 0]
  ------------------
  176|      0|      return std::make_unique<MD4>();
  177|      0|   }
  178|      0|#endif
  179|       |
  180|      0|#if defined(BOTAN_HAS_GOST_34_11)
  181|      0|   if(algo_spec == "GOST-R-34.11-94" || algo_spec == "GOST-34.11") {
  ------------------
  |  Branch (181:7): [True: 0, False: 0]
  |  Branch (181:41): [True: 0, False: 0]
  ------------------
  182|      0|      return std::make_unique<GOST_34_11>();
  183|      0|   }
  184|      0|#endif
  185|       |
  186|      0|#if defined(BOTAN_HAS_ADLER32)
  187|      0|   if(algo_spec == "Adler32") {
  ------------------
  |  Branch (187:7): [True: 0, False: 0]
  ------------------
  188|      0|      return std::make_unique<Adler32>();
  189|      0|   }
  190|      0|#endif
  191|       |
  192|      0|#if defined(BOTAN_HAS_ASCON_HASH256)
  193|      0|   if(algo_spec == "Ascon-Hash256") {
  ------------------
  |  Branch (193:7): [True: 0, False: 0]
  ------------------
  194|      0|      return std::make_unique<Ascon_Hash256>();
  195|      0|   }
  196|      0|#endif
  197|       |
  198|      0|#if defined(BOTAN_HAS_CRC24)
  199|      0|   if(algo_spec == "CRC24") {
  ------------------
  |  Branch (199:7): [True: 0, False: 0]
  ------------------
  200|      0|      return std::make_unique<CRC24>();
  201|      0|   }
  202|      0|#endif
  203|       |
  204|      0|#if defined(BOTAN_HAS_CRC32)
  205|      0|   if(algo_spec == "CRC32") {
  ------------------
  |  Branch (205:7): [True: 0, False: 0]
  ------------------
  206|      0|      return std::make_unique<CRC32>();
  207|      0|   }
  208|      0|#endif
  209|       |
  210|      0|#if defined(BOTAN_HAS_STREEBOG)
  211|      0|   if(algo_spec == "Streebog-256") {
  ------------------
  |  Branch (211:7): [True: 0, False: 0]
  ------------------
  212|      0|      return std::make_unique<Streebog>(256);
  213|      0|   }
  214|      0|   if(algo_spec == "Streebog-512") {
  ------------------
  |  Branch (214:7): [True: 0, False: 0]
  ------------------
  215|      0|      return std::make_unique<Streebog>(512);
  216|      0|   }
  217|      0|#endif
  218|       |
  219|      0|#if defined(BOTAN_HAS_SM3)
  220|      0|   if(algo_spec == "SM3") {
  ------------------
  |  Branch (220:7): [True: 0, False: 0]
  ------------------
  221|      0|      return std::make_unique<SM3>();
  222|      0|   }
  223|      0|#endif
  224|       |
  225|      0|   const SCAN_Name req(algo_spec);
  226|       |
  227|      0|#if defined(BOTAN_HAS_SKEIN_512)
  228|      0|   if(req.algo_name() == "Skein-512") {
  ------------------
  |  Branch (228:7): [True: 0, False: 0]
  ------------------
  229|      0|      return std::make_unique<Skein_512>(req.arg_as_integer(0, 512), req.arg(1, ""));
  230|      0|   }
  231|      0|#endif
  232|       |
  233|      0|#if defined(BOTAN_HAS_BLAKE2B)
  234|      0|   if(req.algo_name() == "Blake2b" || req.algo_name() == "BLAKE2b") {
  ------------------
  |  Branch (234:7): [True: 0, False: 0]
  |  Branch (234:39): [True: 0, False: 0]
  ------------------
  235|      0|      return std::make_unique<BLAKE2b>(req.arg_as_integer(0, 512));
  236|      0|   }
  237|      0|#endif
  238|       |
  239|      0|#if defined(BOTAN_HAS_BLAKE2S)
  240|      0|   if(req.algo_name() == "Blake2s" || req.algo_name() == "BLAKE2s") {
  ------------------
  |  Branch (240:7): [True: 0, False: 0]
  |  Branch (240:39): [True: 0, False: 0]
  ------------------
  241|      0|      return std::make_unique<BLAKE2s>(req.arg_as_integer(0, 256));
  242|      0|   }
  243|      0|#endif
  244|       |
  245|      0|#if defined(BOTAN_HAS_KECCAK)
  246|      0|   if(req.algo_name() == "Keccak-1600") {
  ------------------
  |  Branch (246:7): [True: 0, False: 0]
  ------------------
  247|      0|      return std::make_unique<Keccak_1600>(req.arg_as_integer(0, 512));
  248|      0|   }
  249|      0|#endif
  250|       |
  251|      0|#if defined(BOTAN_HAS_SHA3)
  252|      0|   if(req.algo_name() == "SHA-3") {
  ------------------
  |  Branch (252:7): [True: 0, False: 0]
  ------------------
  253|      0|      return std::make_unique<SHA_3>(req.arg_as_integer(0, 512));
  254|      0|   }
  255|      0|#endif
  256|       |
  257|      0|#if defined(BOTAN_HAS_SHAKE)
  258|      0|   if(req.algo_name() == "SHAKE-128" && req.arg_count() == 1) {
  ------------------
  |  Branch (258:7): [True: 0, False: 0]
  |  Branch (258:41): [True: 0, False: 0]
  ------------------
  259|      0|      return std::make_unique<SHAKE_128>(req.arg_as_integer(0));
  260|      0|   }
  261|      0|   if(req.algo_name() == "SHAKE-256" && req.arg_count() == 1) {
  ------------------
  |  Branch (261:7): [True: 0, False: 0]
  |  Branch (261:41): [True: 0, False: 0]
  ------------------
  262|      0|      return std::make_unique<SHAKE_256>(req.arg_as_integer(0));
  263|      0|   }
  264|      0|#endif
  265|       |
  266|      0|#if defined(BOTAN_HAS_PARALLEL_HASH)
  267|      0|   if(req.algo_name() == "Parallel") {
  ------------------
  |  Branch (267:7): [True: 0, False: 0]
  ------------------
  268|      0|      std::vector<std::unique_ptr<HashFunction>> hashes;
  269|       |
  270|      0|      for(size_t i = 0; i != req.arg_count(); ++i) {
  ------------------
  |  Branch (270:25): [True: 0, False: 0]
  ------------------
  271|      0|         auto h = HashFunction::create(req.arg(i));
  272|      0|         if(!h) {
  ------------------
  |  Branch (272:13): [True: 0, False: 0]
  ------------------
  273|      0|            return nullptr;
  274|      0|         }
  275|      0|         hashes.push_back(std::move(h));
  276|      0|      }
  277|       |
  278|      0|      return std::make_unique<Parallel>(hashes);
  279|      0|   }
  280|      0|#endif
  281|       |
  282|      0|#if defined(BOTAN_HAS_TRUNCATED_HASH)
  283|      0|   if(req.algo_name() == "Truncated" && req.arg_count() == 2) {
  ------------------
  |  Branch (283:7): [True: 0, False: 0]
  |  Branch (283:41): [True: 0, False: 0]
  ------------------
  284|      0|      auto hash = HashFunction::create(req.arg(0));
  285|      0|      if(!hash) {
  ------------------
  |  Branch (285:10): [True: 0, False: 0]
  ------------------
  286|      0|         return nullptr;
  287|      0|      }
  288|       |
  289|      0|      return std::make_unique<Truncated_Hash>(std::move(hash), req.arg_as_integer(1));
  290|      0|   }
  291|      0|#endif
  292|       |
  293|      0|#if defined(BOTAN_HAS_COMB4P)
  294|      0|   if(req.algo_name() == "Comb4P" && req.arg_count() == 2) {
  ------------------
  |  Branch (294:7): [True: 0, False: 0]
  |  Branch (294:38): [True: 0, False: 0]
  ------------------
  295|      0|      auto h1 = HashFunction::create(req.arg(0));
  296|      0|      auto h2 = HashFunction::create(req.arg(1));
  297|       |
  298|      0|      if(h1 && h2) {
  ------------------
  |  Branch (298:10): [True: 0, False: 0]
  |  Branch (298:16): [True: 0, False: 0]
  ------------------
  299|      0|         return std::make_unique<Comb4P>(std::move(h1), std::move(h2));
  300|      0|      }
  301|      0|   }
  302|      0|#endif
  303|       |
  304|      0|   return nullptr;
  305|      0|}
_ZN5Botan12HashFunction15create_or_throwENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_:
  308|  10.4k|std::unique_ptr<HashFunction> HashFunction::create_or_throw(std::string_view algo, std::string_view provider) {
  309|  10.4k|   if(auto hash = HashFunction::create(algo, provider)) {
  ------------------
  |  Branch (309:12): [True: 10.4k, False: 0]
  ------------------
  310|  10.4k|      return hash;
  311|  10.4k|   }
  312|      0|   throw Lookup_Error("Hash", algo, provider);
  313|  10.4k|}

_ZN5Botan5SHA_110compress_nERNSt3__16vectorIjNS_16secure_allocatorIjEEEENS1_4spanIKhLm18446744073709551615EEEm:
   24|  6.60k|void SHA_1::compress_n(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
   25|  6.60k|   using namespace SHA1_F;
   26|       |
   27|  6.60k|#if defined(BOTAN_HAS_SHA1_X86_SHA_NI)
   28|  6.60k|   if(CPUID::has(CPUID::Feature::SHA)) {
  ------------------
  |  Branch (28:7): [True: 0, False: 6.60k]
  ------------------
   29|      0|      return sha1_compress_x86(digest, input, blocks);
   30|      0|   }
   31|  6.60k|#endif
   32|       |
   33|       |#if defined(BOTAN_HAS_SHA1_ARMV8)
   34|       |   if(CPUID::has(CPUID::Feature::SHA1)) {
   35|       |      return sha1_armv8_compress_n(digest, input, blocks);
   36|       |   }
   37|       |#endif
   38|       |
   39|  6.60k|#if defined(BOTAN_HAS_SHA1_AVX2)
   40|  6.60k|   if(CPUID::has(CPUID::Feature::AVX2, CPUID::Feature::BMI)) {
  ------------------
  |  Branch (40:7): [True: 6.60k, False: 0]
  ------------------
   41|  6.60k|      return avx2_compress_n(digest, input, blocks);
   42|  6.60k|   }
   43|      0|#endif
   44|       |
   45|      0|#if defined(BOTAN_HAS_SHA1_SIMD_4X32)
   46|      0|   if(CPUID::has(CPUID::Feature::SIMD_4X32)) {
  ------------------
  |  Branch (46:7): [True: 0, False: 0]
  ------------------
   47|      0|      return simd_compress_n(digest, input, blocks);
   48|      0|   }
   49|      0|#endif
   50|       |
   51|      0|   uint32_t A = digest[0];
   52|      0|   uint32_t B = digest[1];
   53|      0|   uint32_t C = digest[2];
   54|      0|   uint32_t D = digest[3];
   55|      0|   uint32_t E = digest[4];
   56|      0|   std::array<uint32_t, 80> W{};
   57|      0|   auto W_in = std::span{W}.first<block_bytes / sizeof(uint32_t)>();
   58|       |
   59|      0|   BufferSlicer in(input);
   60|       |
   61|      0|   for(size_t i = 0; i != blocks; ++i) {
  ------------------
  |  Branch (61:22): [True: 0, False: 0]
  ------------------
   62|      0|      load_be(W_in, in.take<block_bytes>());
   63|       |
   64|       |      // clang-format off
   65|       |
   66|      0|      for(size_t j = 16; j != 80; j += 8) {
  ------------------
  |  Branch (66:26): [True: 0, False: 0]
  ------------------
   67|      0|         W[j + 0] = rotl<1>(W[j - 3] ^ W[j - 8] ^ W[j - 14] ^ W[j - 16]);
   68|      0|         W[j + 1] = rotl<1>(W[j - 2] ^ W[j - 7] ^ W[j - 13] ^ W[j - 15]);
   69|      0|         W[j + 2] = rotl<1>(W[j - 1] ^ W[j - 6] ^ W[j - 12] ^ W[j - 14]);
   70|      0|         W[j + 3] = rotl<1>(W[j    ] ^ W[j - 5] ^ W[j - 11] ^ W[j - 13]);
   71|      0|         W[j + 4] = rotl<1>(W[j + 1] ^ W[j - 4] ^ W[j - 10] ^ W[j - 12]);
   72|      0|         W[j + 5] = rotl<1>(W[j + 2] ^ W[j - 3] ^ W[j -  9] ^ W[j - 11]);
   73|      0|         W[j + 6] = rotl<1>(W[j + 3] ^ W[j - 2] ^ W[j -  8] ^ W[j - 10]);
   74|      0|         W[j + 7] = rotl<1>(W[j + 4] ^ W[j - 1] ^ W[j -  7] ^ W[j -  9]);
   75|      0|      }
   76|       |
   77|       |      // clang-format on
   78|       |
   79|      0|      F1(A, B, C, D, E, W[0] + K1);
   80|      0|      F1(E, A, B, C, D, W[1] + K1);
   81|      0|      F1(D, E, A, B, C, W[2] + K1);
   82|      0|      F1(C, D, E, A, B, W[3] + K1);
   83|      0|      F1(B, C, D, E, A, W[4] + K1);
   84|      0|      F1(A, B, C, D, E, W[5] + K1);
   85|      0|      F1(E, A, B, C, D, W[6] + K1);
   86|      0|      F1(D, E, A, B, C, W[7] + K1);
   87|      0|      F1(C, D, E, A, B, W[8] + K1);
   88|      0|      F1(B, C, D, E, A, W[9] + K1);
   89|      0|      F1(A, B, C, D, E, W[10] + K1);
   90|      0|      F1(E, A, B, C, D, W[11] + K1);
   91|      0|      F1(D, E, A, B, C, W[12] + K1);
   92|      0|      F1(C, D, E, A, B, W[13] + K1);
   93|      0|      F1(B, C, D, E, A, W[14] + K1);
   94|      0|      F1(A, B, C, D, E, W[15] + K1);
   95|      0|      F1(E, A, B, C, D, W[16] + K1);
   96|      0|      F1(D, E, A, B, C, W[17] + K1);
   97|      0|      F1(C, D, E, A, B, W[18] + K1);
   98|      0|      F1(B, C, D, E, A, W[19] + K1);
   99|       |
  100|      0|      F2(A, B, C, D, E, W[20] + K2);
  101|      0|      F2(E, A, B, C, D, W[21] + K2);
  102|      0|      F2(D, E, A, B, C, W[22] + K2);
  103|      0|      F2(C, D, E, A, B, W[23] + K2);
  104|      0|      F2(B, C, D, E, A, W[24] + K2);
  105|      0|      F2(A, B, C, D, E, W[25] + K2);
  106|      0|      F2(E, A, B, C, D, W[26] + K2);
  107|      0|      F2(D, E, A, B, C, W[27] + K2);
  108|      0|      F2(C, D, E, A, B, W[28] + K2);
  109|      0|      F2(B, C, D, E, A, W[29] + K2);
  110|      0|      F2(A, B, C, D, E, W[30] + K2);
  111|      0|      F2(E, A, B, C, D, W[31] + K2);
  112|      0|      F2(D, E, A, B, C, W[32] + K2);
  113|      0|      F2(C, D, E, A, B, W[33] + K2);
  114|      0|      F2(B, C, D, E, A, W[34] + K2);
  115|      0|      F2(A, B, C, D, E, W[35] + K2);
  116|      0|      F2(E, A, B, C, D, W[36] + K2);
  117|      0|      F2(D, E, A, B, C, W[37] + K2);
  118|      0|      F2(C, D, E, A, B, W[38] + K2);
  119|      0|      F2(B, C, D, E, A, W[39] + K2);
  120|       |
  121|      0|      F3(A, B, C, D, E, W[40] + K3);
  122|      0|      F3(E, A, B, C, D, W[41] + K3);
  123|      0|      F3(D, E, A, B, C, W[42] + K3);
  124|      0|      F3(C, D, E, A, B, W[43] + K3);
  125|      0|      F3(B, C, D, E, A, W[44] + K3);
  126|      0|      F3(A, B, C, D, E, W[45] + K3);
  127|      0|      F3(E, A, B, C, D, W[46] + K3);
  128|      0|      F3(D, E, A, B, C, W[47] + K3);
  129|      0|      F3(C, D, E, A, B, W[48] + K3);
  130|      0|      F3(B, C, D, E, A, W[49] + K3);
  131|      0|      F3(A, B, C, D, E, W[50] + K3);
  132|      0|      F3(E, A, B, C, D, W[51] + K3);
  133|      0|      F3(D, E, A, B, C, W[52] + K3);
  134|      0|      F3(C, D, E, A, B, W[53] + K3);
  135|      0|      F3(B, C, D, E, A, W[54] + K3);
  136|      0|      F3(A, B, C, D, E, W[55] + K3);
  137|      0|      F3(E, A, B, C, D, W[56] + K3);
  138|      0|      F3(D, E, A, B, C, W[57] + K3);
  139|      0|      F3(C, D, E, A, B, W[58] + K3);
  140|      0|      F3(B, C, D, E, A, W[59] + K3);
  141|       |
  142|      0|      F4(A, B, C, D, E, W[60] + K4);
  143|      0|      F4(E, A, B, C, D, W[61] + K4);
  144|      0|      F4(D, E, A, B, C, W[62] + K4);
  145|      0|      F4(C, D, E, A, B, W[63] + K4);
  146|      0|      F4(B, C, D, E, A, W[64] + K4);
  147|      0|      F4(A, B, C, D, E, W[65] + K4);
  148|      0|      F4(E, A, B, C, D, W[66] + K4);
  149|      0|      F4(D, E, A, B, C, W[67] + K4);
  150|      0|      F4(C, D, E, A, B, W[68] + K4);
  151|      0|      F4(B, C, D, E, A, W[69] + K4);
  152|      0|      F4(A, B, C, D, E, W[70] + K4);
  153|      0|      F4(E, A, B, C, D, W[71] + K4);
  154|      0|      F4(D, E, A, B, C, W[72] + K4);
  155|      0|      F4(C, D, E, A, B, W[73] + K4);
  156|      0|      F4(B, C, D, E, A, W[74] + K4);
  157|      0|      F4(A, B, C, D, E, W[75] + K4);
  158|      0|      F4(E, A, B, C, D, W[76] + K4);
  159|      0|      F4(D, E, A, B, C, W[77] + K4);
  160|      0|      F4(C, D, E, A, B, W[78] + K4);
  161|      0|      F4(B, C, D, E, A, W[79] + K4);
  162|       |
  163|      0|      A = (digest[0] += A);
  164|      0|      B = (digest[1] += B);
  165|      0|      C = (digest[2] += C);
  166|      0|      D = (digest[3] += D);
  167|      0|      E = (digest[4] += E);
  168|      0|   }
  169|      0|}
_ZN5Botan5SHA_14initERNSt3__16vectorIjNS_16secure_allocatorIjEEEE:
  174|  6.60k|void SHA_1::init(digest_type& digest) {
  175|  6.60k|   digest.assign({0x67452301, 0xEFCDAB89, 0x98BADCFE, 0x10325476, 0xC3D2E1F0});
  176|  6.60k|}
_ZN5Botan5SHA_18add_dataENSt3__14spanIKhLm18446744073709551615EEE:
  214|  5.28k|void SHA_1::add_data(std::span<const uint8_t> input) {
  215|  5.28k|   m_md.update(input);
  216|  5.28k|}
_ZN5Botan5SHA_112final_resultENSt3__14spanIhLm18446744073709551615EEE:
  218|  5.28k|void SHA_1::final_result(std::span<uint8_t> output) {
  219|  5.28k|   m_md.final(output);
  220|  5.28k|}

_ZN5Botan5SHA_115avx2_compress_nERNSt3__16vectorIjNS_16secure_allocatorIjEEEENS1_4spanIKhLm18446744073709551615EEEm:
  144|  6.60k|void BOTAN_FN_ISA_AVX2_BMI2 SHA_1::avx2_compress_n(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
  145|  6.60k|   using namespace SHA1_F;
  146|       |
  147|  6.60k|   const SIMD_8x32 K11 = SIMD_8x32::splat(K1);
  148|  6.60k|   const SIMD_8x32 K22 = SIMD_8x32::splat(K2);
  149|  6.60k|   const SIMD_8x32 K33 = SIMD_8x32::splat(K3);
  150|  6.60k|   const SIMD_8x32 K44 = SIMD_8x32::splat(K4);
  151|       |
  152|  6.60k|   const SIMD_8x32 K12(K1, K1, K1, K1, K2, K2, K2, K2);
  153|  6.60k|   const SIMD_8x32 K34(K3, K3, K3, K3, K4, K4, K4, K4);
  154|       |
  155|  6.60k|   uint32_t A = digest[0];
  156|  6.60k|   uint32_t B = digest[1];
  157|  6.60k|   uint32_t C = digest[2];
  158|  6.60k|   uint32_t D = digest[3];
  159|  6.60k|   uint32_t E = digest[4];
  160|       |
  161|  6.60k|   BufferSlicer in(input);
  162|       |
  163|  6.60k|   while(blocks >= 2) {
  ------------------
  |  Branch (163:10): [True: 0, False: 6.60k]
  ------------------
  164|      0|      const auto block = in.take(2 * block_bytes);
  165|      0|      blocks -= 2;
  166|       |
  167|      0|      uint32_t W2[80] = {0};
  168|       |
  169|      0|      uint32_t PT[4];
  170|       |
  171|       |      // NOLINTNEXTLINE(*-container-data-pointer)
  172|      0|      SIMD_8x32 XW0 = SIMD_8x32::load_be128(&block[0], &block[64]);
  173|      0|      SIMD_8x32 XW1 = SIMD_8x32::load_be128(&block[16], &block[80]);
  174|      0|      SIMD_8x32 XW2 = SIMD_8x32::load_be128(&block[32], &block[96]);
  175|      0|      SIMD_8x32 XW3 = SIMD_8x32::load_be128(&block[48], &block[112]);
  176|       |
  177|      0|      SIMD_8x32 P0 = XW0 + SIMD_8x32::splat(K1);
  178|      0|      SIMD_8x32 P1 = XW1 + SIMD_8x32::splat(K1);
  179|      0|      SIMD_8x32 P2 = XW2 + SIMD_8x32::splat(K1);
  180|      0|      SIMD_8x32 P3 = XW3 + SIMD_8x32::splat(K1);
  181|       |
  182|       |      // NOLINTBEGIN(readability-suspicious-call-argument) XW rotation
  183|       |
  184|      0|      P0.store_le128(PT, &W2[0]);
  185|      0|      P0 = sha1_avx2_next_w(XW0, XW1, XW2, XW3) + SIMD_8x32::splat(K1);
  186|      0|      F1(A, B, C, D, E, PT[0]);
  187|      0|      F1(E, A, B, C, D, PT[1]);
  188|      0|      F1(D, E, A, B, C, PT[2]);
  189|      0|      F1(C, D, E, A, B, PT[3]);
  190|       |
  191|      0|      P1.store_le128(PT, &W2[4]);
  192|      0|      P1 = sha1_avx2_next_w(XW1, XW2, XW3, XW0) + SIMD_8x32::splat(K2);
  193|      0|      F1(B, C, D, E, A, PT[0]);
  194|      0|      F1(A, B, C, D, E, PT[1]);
  195|      0|      F1(E, A, B, C, D, PT[2]);
  196|      0|      F1(D, E, A, B, C, PT[3]);
  197|       |
  198|      0|      P2.store_le128(PT, &W2[8]);
  199|      0|      P2 = sha1_avx2_next_w(XW2, XW3, XW0, XW1) + SIMD_8x32::splat(K2);
  200|      0|      F1(C, D, E, A, B, PT[0]);
  201|      0|      F1(B, C, D, E, A, PT[1]);
  202|      0|      F1(A, B, C, D, E, PT[2]);
  203|      0|      F1(E, A, B, C, D, PT[3]);
  204|       |
  205|      0|      P3.store_le128(PT, &W2[12]);
  206|      0|      P3 = sha1_avx2_next_w(XW3, XW0, XW1, XW2) + SIMD_8x32::splat(K2);
  207|      0|      F1(D, E, A, B, C, PT[0]);
  208|      0|      F1(C, D, E, A, B, PT[1]);
  209|      0|      F1(B, C, D, E, A, PT[2]);
  210|      0|      F1(A, B, C, D, E, PT[3]);
  211|       |
  212|      0|      P0.store_le128(PT, &W2[16]);
  213|      0|      P0 = sha1_avx2_next_w(XW0, XW1, XW2, XW3) + SIMD_8x32::splat(K2);
  214|      0|      F1(E, A, B, C, D, PT[0]);
  215|      0|      F1(D, E, A, B, C, PT[1]);
  216|      0|      F1(C, D, E, A, B, PT[2]);
  217|      0|      F1(B, C, D, E, A, PT[3]);
  218|       |
  219|      0|      P1.store_le128(PT, &W2[20]);
  220|      0|      P1 = sha1_avx2_next_w(XW1, XW2, XW3, XW0) + SIMD_8x32::splat(K2);
  221|      0|      F2(A, B, C, D, E, PT[0]);
  222|      0|      F2(E, A, B, C, D, PT[1]);
  223|      0|      F2(D, E, A, B, C, PT[2]);
  224|      0|      F2(C, D, E, A, B, PT[3]);
  225|       |
  226|      0|      P2.store_le128(PT, &W2[24]);
  227|      0|      P2 = sha1_avx2_next_w(XW2, XW3, XW0, XW1) + SIMD_8x32::splat(K3);
  228|      0|      F2(B, C, D, E, A, PT[0]);
  229|      0|      F2(A, B, C, D, E, PT[1]);
  230|      0|      F2(E, A, B, C, D, PT[2]);
  231|      0|      F2(D, E, A, B, C, PT[3]);
  232|       |
  233|      0|      P3.store_le128(PT, &W2[28]);
  234|      0|      P3 = sha1_avx2_next_w(XW3, XW0, XW1, XW2) + SIMD_8x32::splat(K3);
  235|      0|      F2(C, D, E, A, B, PT[0]);
  236|      0|      F2(B, C, D, E, A, PT[1]);
  237|      0|      F2(A, B, C, D, E, PT[2]);
  238|      0|      F2(E, A, B, C, D, PT[3]);
  239|       |
  240|      0|      P0.store_le128(PT, &W2[32]);
  241|      0|      P0 = sha1_avx2_next_w(XW0, XW1, XW2, XW3) + SIMD_8x32::splat(K3);
  242|      0|      F2(D, E, A, B, C, PT[0]);
  243|      0|      F2(C, D, E, A, B, PT[1]);
  244|      0|      F2(B, C, D, E, A, PT[2]);
  245|      0|      F2(A, B, C, D, E, PT[3]);
  246|       |
  247|      0|      P1.store_le128(PT, &W2[36]);
  248|      0|      P1 = sha1_avx2_next_w(XW1, XW2, XW3, XW0) + SIMD_8x32::splat(K3);
  249|      0|      F2(E, A, B, C, D, PT[0]);
  250|      0|      F2(D, E, A, B, C, PT[1]);
  251|      0|      F2(C, D, E, A, B, PT[2]);
  252|      0|      F2(B, C, D, E, A, PT[3]);
  253|       |
  254|      0|      P2.store_le128(PT, &W2[40]);
  255|      0|      P2 = sha1_avx2_next_w(XW2, XW3, XW0, XW1) + SIMD_8x32::splat(K3);
  256|      0|      F3(A, B, C, D, E, PT[0]);
  257|      0|      F3(E, A, B, C, D, PT[1]);
  258|      0|      F3(D, E, A, B, C, PT[2]);
  259|      0|      F3(C, D, E, A, B, PT[3]);
  260|       |
  261|      0|      P3.store_le128(PT, &W2[44]);
  262|      0|      P3 = sha1_avx2_next_w(XW3, XW0, XW1, XW2) + SIMD_8x32::splat(K4);
  263|      0|      F3(B, C, D, E, A, PT[0]);
  264|      0|      F3(A, B, C, D, E, PT[1]);
  265|      0|      F3(E, A, B, C, D, PT[2]);
  266|      0|      F3(D, E, A, B, C, PT[3]);
  267|       |
  268|      0|      P0.store_le128(PT, &W2[48]);
  269|      0|      P0 = sha1_avx2_next_w(XW0, XW1, XW2, XW3) + SIMD_8x32::splat(K4);
  270|      0|      F3(C, D, E, A, B, PT[0]);
  271|      0|      F3(B, C, D, E, A, PT[1]);
  272|      0|      F3(A, B, C, D, E, PT[2]);
  273|      0|      F3(E, A, B, C, D, PT[3]);
  274|       |
  275|      0|      P1.store_le128(PT, &W2[52]);
  276|      0|      P1 = sha1_avx2_next_w(XW1, XW2, XW3, XW0) + SIMD_8x32::splat(K4);
  277|      0|      F3(D, E, A, B, C, PT[0]);
  278|      0|      F3(C, D, E, A, B, PT[1]);
  279|      0|      F3(B, C, D, E, A, PT[2]);
  280|      0|      F3(A, B, C, D, E, PT[3]);
  281|       |
  282|      0|      P2.store_le128(PT, &W2[56]);
  283|      0|      P2 = sha1_avx2_next_w(XW2, XW3, XW0, XW1) + SIMD_8x32::splat(K4);
  284|      0|      F3(E, A, B, C, D, PT[0]);
  285|      0|      F3(D, E, A, B, C, PT[1]);
  286|      0|      F3(C, D, E, A, B, PT[2]);
  287|      0|      F3(B, C, D, E, A, PT[3]);
  288|       |
  289|      0|      P3.store_le128(PT, &W2[60]);
  290|      0|      P3 = sha1_avx2_next_w(XW3, XW0, XW1, XW2) + SIMD_8x32::splat(K4);
  291|      0|      F4(A, B, C, D, E, PT[0]);
  292|      0|      F4(E, A, B, C, D, PT[1]);
  293|      0|      F4(D, E, A, B, C, PT[2]);
  294|      0|      F4(C, D, E, A, B, PT[3]);
  295|       |
  296|      0|      P0.store_le128(PT, &W2[64]);
  297|      0|      F4(B, C, D, E, A, PT[0]);
  298|      0|      F4(A, B, C, D, E, PT[1]);
  299|      0|      F4(E, A, B, C, D, PT[2]);
  300|      0|      F4(D, E, A, B, C, PT[3]);
  301|       |
  302|      0|      P1.store_le128(PT, &W2[68]);
  303|      0|      F4(C, D, E, A, B, PT[0]);
  304|      0|      F4(B, C, D, E, A, PT[1]);
  305|      0|      F4(A, B, C, D, E, PT[2]);
  306|      0|      F4(E, A, B, C, D, PT[3]);
  307|       |
  308|      0|      P2.store_le128(PT, &W2[72]);
  309|      0|      F4(D, E, A, B, C, PT[0]);
  310|      0|      F4(C, D, E, A, B, PT[1]);
  311|      0|      F4(B, C, D, E, A, PT[2]);
  312|      0|      F4(A, B, C, D, E, PT[3]);
  313|       |
  314|      0|      P3.store_le128(PT, &W2[76]);
  315|      0|      F4(E, A, B, C, D, PT[0]);
  316|      0|      F4(D, E, A, B, C, PT[1]);
  317|      0|      F4(C, D, E, A, B, PT[2]);
  318|      0|      F4(B, C, D, E, A, PT[3]);
  319|       |
  320|       |      // NOLINTEND(readability-suspicious-call-argument)
  321|       |
  322|      0|      A = (digest[0] += A);
  323|      0|      B = (digest[1] += B);
  324|      0|      C = (digest[2] += C);
  325|      0|      D = (digest[3] += D);
  326|      0|      E = (digest[4] += E);
  327|       |
  328|       |      // Second block with pre-expanded message
  329|      0|      F1(A, B, C, D, E, W2[0]);
  330|      0|      F1(E, A, B, C, D, W2[1]);
  331|      0|      F1(D, E, A, B, C, W2[2]);
  332|      0|      F1(C, D, E, A, B, W2[3]);
  333|      0|      F1(B, C, D, E, A, W2[4]);
  334|      0|      F1(A, B, C, D, E, W2[5]);
  335|      0|      F1(E, A, B, C, D, W2[6]);
  336|      0|      F1(D, E, A, B, C, W2[7]);
  337|      0|      F1(C, D, E, A, B, W2[8]);
  338|      0|      F1(B, C, D, E, A, W2[9]);
  339|      0|      F1(A, B, C, D, E, W2[10]);
  340|      0|      F1(E, A, B, C, D, W2[11]);
  341|      0|      F1(D, E, A, B, C, W2[12]);
  342|      0|      F1(C, D, E, A, B, W2[13]);
  343|      0|      F1(B, C, D, E, A, W2[14]);
  344|      0|      F1(A, B, C, D, E, W2[15]);
  345|      0|      F1(E, A, B, C, D, W2[16]);
  346|      0|      F1(D, E, A, B, C, W2[17]);
  347|      0|      F1(C, D, E, A, B, W2[18]);
  348|      0|      F1(B, C, D, E, A, W2[19]);
  349|      0|      F2(A, B, C, D, E, W2[20]);
  350|      0|      F2(E, A, B, C, D, W2[21]);
  351|      0|      F2(D, E, A, B, C, W2[22]);
  352|      0|      F2(C, D, E, A, B, W2[23]);
  353|      0|      F2(B, C, D, E, A, W2[24]);
  354|      0|      F2(A, B, C, D, E, W2[25]);
  355|      0|      F2(E, A, B, C, D, W2[26]);
  356|      0|      F2(D, E, A, B, C, W2[27]);
  357|      0|      F2(C, D, E, A, B, W2[28]);
  358|      0|      F2(B, C, D, E, A, W2[29]);
  359|      0|      F2(A, B, C, D, E, W2[30]);
  360|      0|      F2(E, A, B, C, D, W2[31]);
  361|      0|      F2(D, E, A, B, C, W2[32]);
  362|      0|      F2(C, D, E, A, B, W2[33]);
  363|      0|      F2(B, C, D, E, A, W2[34]);
  364|      0|      F2(A, B, C, D, E, W2[35]);
  365|      0|      F2(E, A, B, C, D, W2[36]);
  366|      0|      F2(D, E, A, B, C, W2[37]);
  367|      0|      F2(C, D, E, A, B, W2[38]);
  368|      0|      F2(B, C, D, E, A, W2[39]);
  369|      0|      F3(A, B, C, D, E, W2[40]);
  370|      0|      F3(E, A, B, C, D, W2[41]);
  371|      0|      F3(D, E, A, B, C, W2[42]);
  372|      0|      F3(C, D, E, A, B, W2[43]);
  373|      0|      F3(B, C, D, E, A, W2[44]);
  374|      0|      F3(A, B, C, D, E, W2[45]);
  375|      0|      F3(E, A, B, C, D, W2[46]);
  376|      0|      F3(D, E, A, B, C, W2[47]);
  377|      0|      F3(C, D, E, A, B, W2[48]);
  378|      0|      F3(B, C, D, E, A, W2[49]);
  379|      0|      F3(A, B, C, D, E, W2[50]);
  380|      0|      F3(E, A, B, C, D, W2[51]);
  381|      0|      F3(D, E, A, B, C, W2[52]);
  382|      0|      F3(C, D, E, A, B, W2[53]);
  383|      0|      F3(B, C, D, E, A, W2[54]);
  384|      0|      F3(A, B, C, D, E, W2[55]);
  385|      0|      F3(E, A, B, C, D, W2[56]);
  386|      0|      F3(D, E, A, B, C, W2[57]);
  387|      0|      F3(C, D, E, A, B, W2[58]);
  388|      0|      F3(B, C, D, E, A, W2[59]);
  389|      0|      F4(A, B, C, D, E, W2[60]);
  390|      0|      F4(E, A, B, C, D, W2[61]);
  391|      0|      F4(D, E, A, B, C, W2[62]);
  392|      0|      F4(C, D, E, A, B, W2[63]);
  393|      0|      F4(B, C, D, E, A, W2[64]);
  394|      0|      F4(A, B, C, D, E, W2[65]);
  395|      0|      F4(E, A, B, C, D, W2[66]);
  396|      0|      F4(D, E, A, B, C, W2[67]);
  397|      0|      F4(C, D, E, A, B, W2[68]);
  398|      0|      F4(B, C, D, E, A, W2[69]);
  399|      0|      F4(A, B, C, D, E, W2[70]);
  400|      0|      F4(E, A, B, C, D, W2[71]);
  401|      0|      F4(D, E, A, B, C, W2[72]);
  402|      0|      F4(C, D, E, A, B, W2[73]);
  403|      0|      F4(B, C, D, E, A, W2[74]);
  404|      0|      F4(A, B, C, D, E, W2[75]);
  405|      0|      F4(E, A, B, C, D, W2[76]);
  406|      0|      F4(D, E, A, B, C, W2[77]);
  407|      0|      F4(C, D, E, A, B, W2[78]);
  408|      0|      F4(B, C, D, E, A, W2[79]);
  409|       |
  410|      0|      A = (digest[0] += A);
  411|      0|      B = (digest[1] += B);
  412|      0|      C = (digest[2] += C);
  413|      0|      D = (digest[3] += D);
  414|      0|      E = (digest[4] += E);
  415|      0|   }
  416|       |
  417|  13.2k|   for(size_t i = 0; i != blocks; ++i) {
  ------------------
  |  Branch (417:22): [True: 6.60k, False: 6.60k]
  ------------------
  418|  6.60k|      uint32_t PT[8];
  419|       |
  420|  6.60k|      const auto block = in.take(block_bytes);
  421|       |
  422|  6.60k|      SIMD_8x32 W0 = SIMD_8x32::load_be(&block[0]);  // NOLINT(*-container-data-pointer)
  423|  6.60k|      SIMD_8x32 W2 = SIMD_8x32::load_be(&block[32]);
  424|       |
  425|  6.60k|      SIMD_8x32 P0 = W0 + K11;
  426|  6.60k|      SIMD_8x32 P2 = W2 + K11;
  427|       |
  428|  6.60k|      P0.store_le(PT);
  429|  6.60k|      P0 = sha1_avx2_next_w2(W0, W2) + K12;
  430|       |
  431|  6.60k|      F1(A, B, C, D, E, PT[0]);
  432|  6.60k|      F1(E, A, B, C, D, PT[1]);
  433|  6.60k|      F1(D, E, A, B, C, PT[2]);
  434|  6.60k|      F1(C, D, E, A, B, PT[3]);
  435|  6.60k|      F1(B, C, D, E, A, PT[4]);
  436|  6.60k|      F1(A, B, C, D, E, PT[5]);
  437|  6.60k|      F1(E, A, B, C, D, PT[6]);
  438|  6.60k|      F1(D, E, A, B, C, PT[7]);
  439|       |
  440|  6.60k|      P2.store_le(PT);
  441|  6.60k|      P2 = sha1_avx2_next_w2(W2, W0) + K22;
  442|       |
  443|  6.60k|      F1(C, D, E, A, B, PT[0]);
  444|  6.60k|      F1(B, C, D, E, A, PT[1]);
  445|  6.60k|      F1(A, B, C, D, E, PT[2]);
  446|  6.60k|      F1(E, A, B, C, D, PT[3]);
  447|  6.60k|      F1(D, E, A, B, C, PT[4]);
  448|  6.60k|      F1(C, D, E, A, B, PT[5]);
  449|  6.60k|      F1(B, C, D, E, A, PT[6]);
  450|  6.60k|      F1(A, B, C, D, E, PT[7]);
  451|       |
  452|  6.60k|      P0.store_le(PT);
  453|  6.60k|      P0 = sha1_avx2_next_w2(W0, W2) + K22;
  454|       |
  455|  6.60k|      F1(E, A, B, C, D, PT[0]);
  456|  6.60k|      F1(D, E, A, B, C, PT[1]);
  457|  6.60k|      F1(C, D, E, A, B, PT[2]);
  458|  6.60k|      F1(B, C, D, E, A, PT[3]);
  459|  6.60k|      F2(A, B, C, D, E, PT[4]);
  460|  6.60k|      F2(E, A, B, C, D, PT[5]);
  461|  6.60k|      F2(D, E, A, B, C, PT[6]);
  462|  6.60k|      F2(C, D, E, A, B, PT[7]);
  463|       |
  464|  6.60k|      P2.store_le(PT);
  465|  6.60k|      P2 = sha1_avx2_next_w2(W2, W0) + K33;
  466|       |
  467|  6.60k|      F2(B, C, D, E, A, PT[0]);
  468|  6.60k|      F2(A, B, C, D, E, PT[1]);
  469|  6.60k|      F2(E, A, B, C, D, PT[2]);
  470|  6.60k|      F2(D, E, A, B, C, PT[3]);
  471|  6.60k|      F2(C, D, E, A, B, PT[4]);
  472|  6.60k|      F2(B, C, D, E, A, PT[5]);
  473|  6.60k|      F2(A, B, C, D, E, PT[6]);
  474|  6.60k|      F2(E, A, B, C, D, PT[7]);
  475|       |
  476|  6.60k|      P0.store_le(PT);
  477|  6.60k|      P0 = sha1_avx2_next_w2(W0, W2) + K33;
  478|       |
  479|  6.60k|      F2(D, E, A, B, C, PT[0]);
  480|  6.60k|      F2(C, D, E, A, B, PT[1]);
  481|  6.60k|      F2(B, C, D, E, A, PT[2]);
  482|  6.60k|      F2(A, B, C, D, E, PT[3]);
  483|  6.60k|      F2(E, A, B, C, D, PT[4]);
  484|  6.60k|      F2(D, E, A, B, C, PT[5]);
  485|  6.60k|      F2(C, D, E, A, B, PT[6]);
  486|  6.60k|      F2(B, C, D, E, A, PT[7]);
  487|       |
  488|  6.60k|      P2.store_le(PT);
  489|  6.60k|      P2 = sha1_avx2_next_w2(W2, W0) + K34;
  490|       |
  491|  6.60k|      F3(A, B, C, D, E, PT[0]);
  492|  6.60k|      F3(E, A, B, C, D, PT[1]);
  493|  6.60k|      F3(D, E, A, B, C, PT[2]);
  494|  6.60k|      F3(C, D, E, A, B, PT[3]);
  495|  6.60k|      F3(B, C, D, E, A, PT[4]);
  496|  6.60k|      F3(A, B, C, D, E, PT[5]);
  497|  6.60k|      F3(E, A, B, C, D, PT[6]);
  498|  6.60k|      F3(D, E, A, B, C, PT[7]);
  499|       |
  500|  6.60k|      P0.store_le(PT);
  501|  6.60k|      P0 = sha1_avx2_next_w2(W0, W2) + K44;
  502|       |
  503|  6.60k|      F3(C, D, E, A, B, PT[0]);
  504|  6.60k|      F3(B, C, D, E, A, PT[1]);
  505|  6.60k|      F3(A, B, C, D, E, PT[2]);
  506|  6.60k|      F3(E, A, B, C, D, PT[3]);
  507|  6.60k|      F3(D, E, A, B, C, PT[4]);
  508|  6.60k|      F3(C, D, E, A, B, PT[5]);
  509|  6.60k|      F3(B, C, D, E, A, PT[6]);
  510|  6.60k|      F3(A, B, C, D, E, PT[7]);
  511|       |
  512|  6.60k|      P2.store_le(PT);
  513|  6.60k|      P2 = sha1_avx2_next_w2(W2, W0) + K44;
  514|       |
  515|  6.60k|      F3(E, A, B, C, D, PT[0]);
  516|  6.60k|      F3(D, E, A, B, C, PT[1]);
  517|  6.60k|      F3(C, D, E, A, B, PT[2]);
  518|  6.60k|      F3(B, C, D, E, A, PT[3]);
  519|  6.60k|      F4(A, B, C, D, E, PT[4]);
  520|  6.60k|      F4(E, A, B, C, D, PT[5]);
  521|  6.60k|      F4(D, E, A, B, C, PT[6]);
  522|  6.60k|      F4(C, D, E, A, B, PT[7]);
  523|       |
  524|  6.60k|      P0.store_le(PT);
  525|       |
  526|  6.60k|      F4(B, C, D, E, A, PT[0]);
  527|  6.60k|      F4(A, B, C, D, E, PT[1]);
  528|  6.60k|      F4(E, A, B, C, D, PT[2]);
  529|  6.60k|      F4(D, E, A, B, C, PT[3]);
  530|  6.60k|      F4(C, D, E, A, B, PT[4]);
  531|  6.60k|      F4(B, C, D, E, A, PT[5]);
  532|  6.60k|      F4(A, B, C, D, E, PT[6]);
  533|  6.60k|      F4(E, A, B, C, D, PT[7]);
  534|       |
  535|  6.60k|      P2.store_le(PT);
  536|       |
  537|  6.60k|      F4(D, E, A, B, C, PT[0]);
  538|  6.60k|      F4(C, D, E, A, B, PT[1]);
  539|  6.60k|      F4(B, C, D, E, A, PT[2]);
  540|  6.60k|      F4(A, B, C, D, E, PT[3]);
  541|  6.60k|      F4(E, A, B, C, D, PT[4]);
  542|  6.60k|      F4(D, E, A, B, C, PT[5]);
  543|  6.60k|      F4(C, D, E, A, B, PT[6]);
  544|  6.60k|      F4(B, C, D, E, A, PT[7]);
  545|       |
  546|  6.60k|      A = (digest[0] += A);
  547|  6.60k|      B = (digest[1] += B);
  548|  6.60k|      C = (digest[2] += C);
  549|  6.60k|      D = (digest[3] += D);
  550|  6.60k|      E = (digest[4] += E);
  551|  6.60k|   }
  552|  6.60k|}
sha1_avx2.cpp:_ZN5Botan12_GLOBAL__N_117sha1_avx2_next_w2ERNS_9SIMD_8x32ES1_:
  115|  52.8k|BOTAN_FN_ISA_AVX2_BMI2 BOTAN_FORCE_INLINE SIMD_8x32 sha1_avx2_next_w2(SIMD_8x32& W0, SIMD_8x32 W2) {
  116|       |   // W[j-16..j-9] ^ W[j-8...j-1]
  117|  52.8k|   auto WN = W0 ^ W2;
  118|       |
  119|       |   // XOR in W[j-3..j-1] || 0 || 0 || 0 || W[j-8...j-7]
  120|  52.8k|   WN ^= permute_words<5, 6, 7, -1, -1, -1, 0, 1>(W2);
  121|       |
  122|       |   // XOR in W[j-14...j-9] || 0 || 0
  123|  52.8k|   WN ^= permute_words<2, 3, 4, 5, 6, 7, -1, -1>(W0);
  124|       |
  125|       |   // Extract W[j...j+2], rotate, and XOR into W[j+3...j+5]
  126|  52.8k|   auto T0 = permute_words<-1, -1, -1, 0, 1, 2, -1, -1>(WN).rotl<2>();
  127|  52.8k|   WN = WN.rotl<1>();  // main block rotation
  128|       |
  129|  52.8k|   WN ^= T0;
  130|       |
  131|       |   // Extract W[j+3...j+4], rotate, and XOR into W[j+6...j+7]
  132|  52.8k|   WN ^= permute_words<-1, -1, -1, -1, -1, -1, 3, 4>(WN).rotl<1>();
  133|       |
  134|  52.8k|   W0 = WN;
  135|  52.8k|   return WN;
  136|  52.8k|}
sha1_avx2.cpp:_ZN5Botan12_GLOBAL__N_113permute_wordsILi5ELi6ELi7ELin1ELin1ELin1ELi0ELi1EEENS_9SIMD_8x32ES2_:
   58|  52.8k|BOTAN_FN_ISA_AVX2_BMI2 BOTAN_FORCE_INLINE SIMD_8x32 permute_words(SIMD_8x32 v) {
   59|  52.8k|   const __m256i tbl = _mm256_setr_epi32(I0, I1, I2, I3, I4, I5, I6, I7);
   60|  52.8k|   const __m256i mask = _mm256_setr_epi32(I0 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (60:43): [True: 52.8k, Folded]
  ------------------
   61|  52.8k|                                          I1 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (61:43): [True: 52.8k, Folded]
  ------------------
   62|  52.8k|                                          I2 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (62:43): [True: 52.8k, Folded]
  ------------------
   63|  52.8k|                                          I3 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (63:43): [Folded, False: 52.8k]
  ------------------
   64|  52.8k|                                          I4 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (64:43): [Folded, False: 52.8k]
  ------------------
   65|  52.8k|                                          I5 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (65:43): [Folded, False: 52.8k]
  ------------------
   66|  52.8k|                                          I6 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (66:43): [True: 52.8k, Folded]
  ------------------
   67|  52.8k|                                          I7 >= 0 ? 0xFFFFFFFF : 0);
  ------------------
  |  Branch (67:43): [True: 52.8k, Folded]
  ------------------
   68|       |
   69|  52.8k|   return SIMD_8x32(_mm256_and_si256(mask, _mm256_permutevar8x32_epi32(v.raw(), tbl)));
   70|  52.8k|}
sha1_avx2.cpp:_ZN5Botan12_GLOBAL__N_113permute_wordsILi2ELi3ELi4ELi5ELi6ELi7ELin1ELin1EEENS_9SIMD_8x32ES2_:
   58|  52.8k|BOTAN_FN_ISA_AVX2_BMI2 BOTAN_FORCE_INLINE SIMD_8x32 permute_words(SIMD_8x32 v) {
   59|  52.8k|   const __m256i tbl = _mm256_setr_epi32(I0, I1, I2, I3, I4, I5, I6, I7);
   60|  52.8k|   const __m256i mask = _mm256_setr_epi32(I0 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (60:43): [True: 52.8k, Folded]
  ------------------
   61|  52.8k|                                          I1 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (61:43): [True: 52.8k, Folded]
  ------------------
   62|  52.8k|                                          I2 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (62:43): [True: 52.8k, Folded]
  ------------------
   63|  52.8k|                                          I3 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (63:43): [True: 52.8k, Folded]
  ------------------
   64|  52.8k|                                          I4 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (64:43): [True: 52.8k, Folded]
  ------------------
   65|  52.8k|                                          I5 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (65:43): [True: 52.8k, Folded]
  ------------------
   66|  52.8k|                                          I6 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (66:43): [Folded, False: 52.8k]
  ------------------
   67|  52.8k|                                          I7 >= 0 ? 0xFFFFFFFF : 0);
  ------------------
  |  Branch (67:43): [Folded, False: 52.8k]
  ------------------
   68|       |
   69|  52.8k|   return SIMD_8x32(_mm256_and_si256(mask, _mm256_permutevar8x32_epi32(v.raw(), tbl)));
   70|  52.8k|}
sha1_avx2.cpp:_ZN5Botan12_GLOBAL__N_113permute_wordsILin1ELin1ELin1ELi0ELi1ELi2ELin1ELin1EEENS_9SIMD_8x32ES2_:
   58|  52.8k|BOTAN_FN_ISA_AVX2_BMI2 BOTAN_FORCE_INLINE SIMD_8x32 permute_words(SIMD_8x32 v) {
   59|  52.8k|   const __m256i tbl = _mm256_setr_epi32(I0, I1, I2, I3, I4, I5, I6, I7);
   60|  52.8k|   const __m256i mask = _mm256_setr_epi32(I0 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (60:43): [Folded, False: 52.8k]
  ------------------
   61|  52.8k|                                          I1 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (61:43): [Folded, False: 52.8k]
  ------------------
   62|  52.8k|                                          I2 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (62:43): [Folded, False: 52.8k]
  ------------------
   63|  52.8k|                                          I3 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (63:43): [True: 52.8k, Folded]
  ------------------
   64|  52.8k|                                          I4 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (64:43): [True: 52.8k, Folded]
  ------------------
   65|  52.8k|                                          I5 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (65:43): [True: 52.8k, Folded]
  ------------------
   66|  52.8k|                                          I6 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (66:43): [Folded, False: 52.8k]
  ------------------
   67|  52.8k|                                          I7 >= 0 ? 0xFFFFFFFF : 0);
  ------------------
  |  Branch (67:43): [Folded, False: 52.8k]
  ------------------
   68|       |
   69|  52.8k|   return SIMD_8x32(_mm256_and_si256(mask, _mm256_permutevar8x32_epi32(v.raw(), tbl)));
   70|  52.8k|}
sha1_avx2.cpp:_ZN5Botan12_GLOBAL__N_113permute_wordsILin1ELin1ELin1ELin1ELin1ELin1ELi3ELi4EEENS_9SIMD_8x32ES2_:
   58|  52.8k|BOTAN_FN_ISA_AVX2_BMI2 BOTAN_FORCE_INLINE SIMD_8x32 permute_words(SIMD_8x32 v) {
   59|  52.8k|   const __m256i tbl = _mm256_setr_epi32(I0, I1, I2, I3, I4, I5, I6, I7);
   60|  52.8k|   const __m256i mask = _mm256_setr_epi32(I0 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (60:43): [Folded, False: 52.8k]
  ------------------
   61|  52.8k|                                          I1 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (61:43): [Folded, False: 52.8k]
  ------------------
   62|  52.8k|                                          I2 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (62:43): [Folded, False: 52.8k]
  ------------------
   63|  52.8k|                                          I3 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (63:43): [Folded, False: 52.8k]
  ------------------
   64|  52.8k|                                          I4 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (64:43): [Folded, False: 52.8k]
  ------------------
   65|  52.8k|                                          I5 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (65:43): [Folded, False: 52.8k]
  ------------------
   66|  52.8k|                                          I6 >= 0 ? 0xFFFFFFFF : 0,
  ------------------
  |  Branch (66:43): [True: 52.8k, Folded]
  ------------------
   67|  52.8k|                                          I7 >= 0 ? 0xFFFFFFFF : 0);
  ------------------
  |  Branch (67:43): [True: 52.8k, Folded]
  ------------------
   68|       |
   69|  52.8k|   return SIMD_8x32(_mm256_and_si256(mask, _mm256_permutevar8x32_epi32(v.raw(), tbl)));
   70|  52.8k|}

_ZN5Botan7SHA_25615compress_digestERNSt3__16vectorIjNS_16secure_allocatorIjEEEENS1_4spanIKhLm18446744073709551615EEEm:
   59|  54.0k|                                                             size_t blocks) {
   60|  54.0k|#if defined(BOTAN_HAS_SHA2_32_X86)
   61|  54.0k|   if(CPUID::has(CPUID::Feature::SHA)) {
  ------------------
  |  Branch (61:7): [True: 0, False: 54.0k]
  ------------------
   62|      0|      return SHA_256::compress_digest_x86(digest, input, blocks);
   63|      0|   }
   64|  54.0k|#endif
   65|       |
   66|       |#if defined(BOTAN_HAS_SHA2_32_ARMV8)
   67|       |   if(CPUID::has(CPUID::Feature::SHA2)) {
   68|       |      return SHA_256::compress_digest_armv8(digest, input, blocks);
   69|       |   }
   70|       |#endif
   71|       |
   72|  54.0k|#if defined(BOTAN_HAS_SHA2_32_X86_AVX2)
   73|  54.0k|   if(CPUID::has(CPUID::Feature::AVX2, CPUID::Feature::BMI)) {
  ------------------
  |  Branch (73:7): [True: 54.0k, False: 0]
  ------------------
   74|  54.0k|      return SHA_256::compress_digest_x86_avx2(digest, input, blocks);
   75|  54.0k|   }
   76|      0|#endif
   77|       |
   78|      0|#if defined(BOTAN_HAS_SHA2_32_SIMD)
   79|      0|   if(CPUID::has(CPUID::Feature::SIMD_4X32)) {
  ------------------
  |  Branch (79:7): [True: 0, False: 0]
  ------------------
   80|      0|      return SHA_256::compress_digest_x86_simd(digest, input, blocks);
   81|      0|   }
   82|      0|#endif
   83|       |
   84|      0|   uint32_t A = digest[0];
   85|      0|   uint32_t B = digest[1];
   86|      0|   uint32_t C = digest[2];
   87|      0|   uint32_t D = digest[3];
   88|      0|   uint32_t E = digest[4];
   89|      0|   uint32_t F = digest[5];
   90|      0|   uint32_t G = digest[6];
   91|      0|   uint32_t H = digest[7];
   92|       |
   93|      0|   std::array<uint32_t, 16> W{};
   94|       |
   95|      0|   BufferSlicer in(input);
   96|       |
   97|      0|   for(size_t i = 0; i != blocks; ++i) {
  ------------------
  |  Branch (97:22): [True: 0, False: 0]
  ------------------
   98|      0|      load_be(W, in.take<block_bytes>());
   99|       |
  100|       |      // clang-format off
  101|       |
  102|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], SHA256_K[ 0]);
  103|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], SHA256_K[ 1]);
  104|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], SHA256_K[ 2]);
  105|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], SHA256_K[ 3]);
  106|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], SHA256_K[ 4]);
  107|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], SHA256_K[ 5]);
  108|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], SHA256_K[ 6]);
  109|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], SHA256_K[ 7]);
  110|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], SHA256_K[ 8]);
  111|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], SHA256_K[ 9]);
  112|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], SHA256_K[10]);
  113|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], SHA256_K[11]);
  114|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], SHA256_K[12]);
  115|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], SHA256_K[13]);
  116|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], SHA256_K[14]);
  117|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], SHA256_K[15]);
  118|       |
  119|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], SHA256_K[16]);
  120|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], SHA256_K[17]);
  121|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], SHA256_K[18]);
  122|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], SHA256_K[19]);
  123|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], SHA256_K[20]);
  124|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], SHA256_K[21]);
  125|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], SHA256_K[22]);
  126|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], SHA256_K[23]);
  127|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], SHA256_K[24]);
  128|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], SHA256_K[25]);
  129|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], SHA256_K[26]);
  130|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], SHA256_K[27]);
  131|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], SHA256_K[28]);
  132|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], SHA256_K[29]);
  133|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], SHA256_K[30]);
  134|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], SHA256_K[31]);
  135|       |
  136|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], SHA256_K[32]);
  137|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], SHA256_K[33]);
  138|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], SHA256_K[34]);
  139|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], SHA256_K[35]);
  140|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], SHA256_K[36]);
  141|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], SHA256_K[37]);
  142|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], SHA256_K[38]);
  143|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], SHA256_K[39]);
  144|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], SHA256_K[40]);
  145|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], SHA256_K[41]);
  146|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], SHA256_K[42]);
  147|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], SHA256_K[43]);
  148|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], SHA256_K[44]);
  149|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], SHA256_K[45]);
  150|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], SHA256_K[46]);
  151|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], SHA256_K[47]);
  152|       |
  153|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], SHA256_K[48]);
  154|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], SHA256_K[49]);
  155|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], SHA256_K[50]);
  156|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], SHA256_K[51]);
  157|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], SHA256_K[52]);
  158|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], SHA256_K[53]);
  159|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], SHA256_K[54]);
  160|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], SHA256_K[55]);
  161|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], SHA256_K[56]);
  162|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], SHA256_K[57]);
  163|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], SHA256_K[58]);
  164|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], SHA256_K[59]);
  165|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], SHA256_K[60]);
  166|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], SHA256_K[61]);
  167|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], SHA256_K[62]);
  168|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], SHA256_K[63]);
  169|       |
  170|       |      // clang-format on
  171|       |
  172|      0|      A = (digest[0] += A);
  173|      0|      B = (digest[1] += B);
  174|      0|      C = (digest[2] += C);
  175|      0|      D = (digest[3] += D);
  176|      0|      E = (digest[4] += E);
  177|      0|      F = (digest[5] += F);
  178|      0|      G = (digest[6] += G);
  179|      0|      H = (digest[7] += H);
  180|      0|   }
  181|      0|}
_ZN5Botan7SHA_25610compress_nERNSt3__16vectorIjNS_16secure_allocatorIjEEEENS1_4spanIKhLm18446744073709551615EEEm:
  215|  54.0k|void SHA_256::compress_n(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
  216|  54.0k|   SHA_256::compress_digest(digest, input, blocks);
  217|  54.0k|}
_ZN5Botan7SHA_2564initERNSt3__16vectorIjNS_16secure_allocatorIjEEEE:
  219|  47.2k|void SHA_256::init(digest_type& digest) {
  220|  47.2k|   digest.assign({0x6A09E667, 0xBB67AE85, 0x3C6EF372, 0xA54FF53A, 0x510E527F, 0x9B05688C, 0x1F83D9AB, 0x5BE0CD19});
  221|  47.2k|}
_ZNK5Botan7SHA_25610copy_stateEv:
  227|  28.9k|std::unique_ptr<HashFunction> SHA_256::copy_state() const {
  228|  28.9k|   return std::make_unique<SHA_256>(*this);
  229|  28.9k|}
_ZN5Botan7SHA_2568add_dataENSt3__14spanIKhLm18446744073709551615EEE:
  231|  39.5k|void SHA_256::add_data(std::span<const uint8_t> input) {
  232|  39.5k|   m_md.update(input);
  233|  39.5k|}
_ZN5Botan7SHA_25612final_resultENSt3__14spanIhLm18446744073709551615EEE:
  235|  36.8k|void SHA_256::final_result(std::span<uint8_t> output) {
  236|  36.8k|   m_md.final(output);
  237|  36.8k|}

_ZN5Botan7SHA_25624compress_digest_x86_avx2ERNSt3__16vectorIjNS_16secure_allocatorIjEEEENS1_4spanIKhLm18446744073709551615EEEm:
  100|  54.0k|   digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
  101|  54.0k|   alignas(64) uint32_t W[16];
  102|  54.0k|   alignas(64) uint32_t W2[64];
  103|       |
  104|  54.0k|   uint32_t A = digest[0];
  105|  54.0k|   uint32_t B = digest[1];
  106|  54.0k|   uint32_t C = digest[2];
  107|  54.0k|   uint32_t D = digest[3];
  108|  54.0k|   uint32_t E = digest[4];
  109|  54.0k|   uint32_t F = digest[5];
  110|  54.0k|   uint32_t G = digest[6];
  111|  54.0k|   uint32_t H = digest[7];
  112|       |
  113|  54.0k|   const uint8_t* data = input.data();
  114|       |
  115|  55.2k|   while(blocks >= 2) {
  ------------------
  |  Branch (115:10): [True: 1.15k, False: 54.0k]
  ------------------
  116|  1.15k|      SIMD_8x32 WS[4];
  117|       |
  118|  5.76k|      for(size_t i = 0; i < 4; i++) {
  ------------------
  |  Branch (118:25): [True: 4.61k, False: 1.15k]
  ------------------
  119|  4.61k|         WS[i] = SIMD_8x32::load_be128(&data[16 * i], &data[64 + 16 * i]);
  120|  4.61k|         auto WK = WS[i] + SIMD_8x32::load_le128(&SHA256_K[4 * i]);
  121|  4.61k|         WK.store_le128(&W[4 * i], &W2[4 * i]);
  122|  4.61k|      }
  123|       |
  124|  1.15k|      data += 2 * 64;
  125|  1.15k|      blocks -= 2;
  126|       |
  127|  4.61k|      for(size_t r = 0; r != 48; r += 16) {
  ------------------
  |  Branch (127:25): [True: 3.45k, False: 1.15k]
  ------------------
  128|  3.45k|         auto w = next_w(WS) + SIMD_8x32::load_le128(&SHA256_K[r + 16]);
  129|       |
  130|  3.45k|         SHA2_32_F(A, B, C, D, E, F, G, H, W[0]);
  131|  3.45k|         SHA2_32_F(H, A, B, C, D, E, F, G, W[1]);
  132|  3.45k|         SHA2_32_F(G, H, A, B, C, D, E, F, W[2]);
  133|  3.45k|         SHA2_32_F(F, G, H, A, B, C, D, E, W[3]);
  134|       |
  135|  3.45k|         w.store_le128(&W[0], &W2[r + 16]);
  136|       |
  137|  3.45k|         w = next_w(WS) + SIMD_8x32::load_le128(&SHA256_K[r + 20]);
  138|       |
  139|  3.45k|         SHA2_32_F(E, F, G, H, A, B, C, D, W[4]);
  140|  3.45k|         SHA2_32_F(D, E, F, G, H, A, B, C, W[5]);
  141|  3.45k|         SHA2_32_F(C, D, E, F, G, H, A, B, W[6]);
  142|  3.45k|         SHA2_32_F(B, C, D, E, F, G, H, A, W[7]);
  143|       |
  144|  3.45k|         w.store_le128(&W[4], &W2[r + 20]);
  145|       |
  146|  3.45k|         w = next_w(WS) + SIMD_8x32::load_le128(&SHA256_K[r + 24]);
  147|       |
  148|  3.45k|         SHA2_32_F(A, B, C, D, E, F, G, H, W[8]);
  149|  3.45k|         SHA2_32_F(H, A, B, C, D, E, F, G, W[9]);
  150|  3.45k|         SHA2_32_F(G, H, A, B, C, D, E, F, W[10]);
  151|  3.45k|         SHA2_32_F(F, G, H, A, B, C, D, E, W[11]);
  152|       |
  153|  3.45k|         w.store_le128(&W[8], &W2[r + 24]);
  154|       |
  155|  3.45k|         w = next_w(WS) + SIMD_8x32::load_le128(&SHA256_K[r + 28]);
  156|       |
  157|  3.45k|         SHA2_32_F(E, F, G, H, A, B, C, D, W[12]);
  158|  3.45k|         SHA2_32_F(D, E, F, G, H, A, B, C, W[13]);
  159|  3.45k|         SHA2_32_F(C, D, E, F, G, H, A, B, W[14]);
  160|  3.45k|         SHA2_32_F(B, C, D, E, F, G, H, A, W[15]);
  161|       |
  162|  3.45k|         w.store_le128(&W[12], &W2[r + 28]);
  163|  3.45k|      }
  164|       |
  165|  1.15k|      SHA2_32_F(A, B, C, D, E, F, G, H, W[0]);
  166|  1.15k|      SHA2_32_F(H, A, B, C, D, E, F, G, W[1]);
  167|  1.15k|      SHA2_32_F(G, H, A, B, C, D, E, F, W[2]);
  168|  1.15k|      SHA2_32_F(F, G, H, A, B, C, D, E, W[3]);
  169|  1.15k|      SHA2_32_F(E, F, G, H, A, B, C, D, W[4]);
  170|  1.15k|      SHA2_32_F(D, E, F, G, H, A, B, C, W[5]);
  171|  1.15k|      SHA2_32_F(C, D, E, F, G, H, A, B, W[6]);
  172|  1.15k|      SHA2_32_F(B, C, D, E, F, G, H, A, W[7]);
  173|  1.15k|      SHA2_32_F(A, B, C, D, E, F, G, H, W[8]);
  174|  1.15k|      SHA2_32_F(H, A, B, C, D, E, F, G, W[9]);
  175|  1.15k|      SHA2_32_F(G, H, A, B, C, D, E, F, W[10]);
  176|  1.15k|      SHA2_32_F(F, G, H, A, B, C, D, E, W[11]);
  177|  1.15k|      SHA2_32_F(E, F, G, H, A, B, C, D, W[12]);
  178|  1.15k|      SHA2_32_F(D, E, F, G, H, A, B, C, W[13]);
  179|  1.15k|      SHA2_32_F(C, D, E, F, G, H, A, B, W[14]);
  180|  1.15k|      SHA2_32_F(B, C, D, E, F, G, H, A, W[15]);
  181|       |
  182|  1.15k|      A = (digest[0] += A);
  183|  1.15k|      B = (digest[1] += B);
  184|  1.15k|      C = (digest[2] += C);
  185|  1.15k|      D = (digest[3] += D);
  186|  1.15k|      E = (digest[4] += E);
  187|  1.15k|      F = (digest[5] += F);
  188|  1.15k|      G = (digest[6] += G);
  189|  1.15k|      H = (digest[7] += H);
  190|       |
  191|       |      // Now the second block, with already expanded message
  192|  1.15k|      SHA2_32_F(A, B, C, D, E, F, G, H, W2[0]);
  193|  1.15k|      SHA2_32_F(H, A, B, C, D, E, F, G, W2[1]);
  194|  1.15k|      SHA2_32_F(G, H, A, B, C, D, E, F, W2[2]);
  195|  1.15k|      SHA2_32_F(F, G, H, A, B, C, D, E, W2[3]);
  196|  1.15k|      SHA2_32_F(E, F, G, H, A, B, C, D, W2[4]);
  197|  1.15k|      SHA2_32_F(D, E, F, G, H, A, B, C, W2[5]);
  198|  1.15k|      SHA2_32_F(C, D, E, F, G, H, A, B, W2[6]);
  199|  1.15k|      SHA2_32_F(B, C, D, E, F, G, H, A, W2[7]);
  200|  1.15k|      SHA2_32_F(A, B, C, D, E, F, G, H, W2[8]);
  201|  1.15k|      SHA2_32_F(H, A, B, C, D, E, F, G, W2[9]);
  202|  1.15k|      SHA2_32_F(G, H, A, B, C, D, E, F, W2[10]);
  203|  1.15k|      SHA2_32_F(F, G, H, A, B, C, D, E, W2[11]);
  204|  1.15k|      SHA2_32_F(E, F, G, H, A, B, C, D, W2[12]);
  205|  1.15k|      SHA2_32_F(D, E, F, G, H, A, B, C, W2[13]);
  206|  1.15k|      SHA2_32_F(C, D, E, F, G, H, A, B, W2[14]);
  207|  1.15k|      SHA2_32_F(B, C, D, E, F, G, H, A, W2[15]);
  208|       |
  209|  1.15k|      SHA2_32_F(A, B, C, D, E, F, G, H, W2[16]);
  210|  1.15k|      SHA2_32_F(H, A, B, C, D, E, F, G, W2[17]);
  211|  1.15k|      SHA2_32_F(G, H, A, B, C, D, E, F, W2[18]);
  212|  1.15k|      SHA2_32_F(F, G, H, A, B, C, D, E, W2[19]);
  213|  1.15k|      SHA2_32_F(E, F, G, H, A, B, C, D, W2[20]);
  214|  1.15k|      SHA2_32_F(D, E, F, G, H, A, B, C, W2[21]);
  215|  1.15k|      SHA2_32_F(C, D, E, F, G, H, A, B, W2[22]);
  216|  1.15k|      SHA2_32_F(B, C, D, E, F, G, H, A, W2[23]);
  217|  1.15k|      SHA2_32_F(A, B, C, D, E, F, G, H, W2[24]);
  218|  1.15k|      SHA2_32_F(H, A, B, C, D, E, F, G, W2[25]);
  219|  1.15k|      SHA2_32_F(G, H, A, B, C, D, E, F, W2[26]);
  220|  1.15k|      SHA2_32_F(F, G, H, A, B, C, D, E, W2[27]);
  221|  1.15k|      SHA2_32_F(E, F, G, H, A, B, C, D, W2[28]);
  222|  1.15k|      SHA2_32_F(D, E, F, G, H, A, B, C, W2[29]);
  223|  1.15k|      SHA2_32_F(C, D, E, F, G, H, A, B, W2[30]);
  224|  1.15k|      SHA2_32_F(B, C, D, E, F, G, H, A, W2[31]);
  225|       |
  226|  1.15k|      SHA2_32_F(A, B, C, D, E, F, G, H, W2[32]);
  227|  1.15k|      SHA2_32_F(H, A, B, C, D, E, F, G, W2[33]);
  228|  1.15k|      SHA2_32_F(G, H, A, B, C, D, E, F, W2[34]);
  229|  1.15k|      SHA2_32_F(F, G, H, A, B, C, D, E, W2[35]);
  230|  1.15k|      SHA2_32_F(E, F, G, H, A, B, C, D, W2[36]);
  231|  1.15k|      SHA2_32_F(D, E, F, G, H, A, B, C, W2[37]);
  232|  1.15k|      SHA2_32_F(C, D, E, F, G, H, A, B, W2[38]);
  233|  1.15k|      SHA2_32_F(B, C, D, E, F, G, H, A, W2[39]);
  234|  1.15k|      SHA2_32_F(A, B, C, D, E, F, G, H, W2[40]);
  235|  1.15k|      SHA2_32_F(H, A, B, C, D, E, F, G, W2[41]);
  236|  1.15k|      SHA2_32_F(G, H, A, B, C, D, E, F, W2[42]);
  237|  1.15k|      SHA2_32_F(F, G, H, A, B, C, D, E, W2[43]);
  238|  1.15k|      SHA2_32_F(E, F, G, H, A, B, C, D, W2[44]);
  239|  1.15k|      SHA2_32_F(D, E, F, G, H, A, B, C, W2[45]);
  240|  1.15k|      SHA2_32_F(C, D, E, F, G, H, A, B, W2[46]);
  241|  1.15k|      SHA2_32_F(B, C, D, E, F, G, H, A, W2[47]);
  242|       |
  243|  1.15k|      SHA2_32_F(A, B, C, D, E, F, G, H, W2[48]);
  244|  1.15k|      SHA2_32_F(H, A, B, C, D, E, F, G, W2[49]);
  245|  1.15k|      SHA2_32_F(G, H, A, B, C, D, E, F, W2[50]);
  246|  1.15k|      SHA2_32_F(F, G, H, A, B, C, D, E, W2[51]);
  247|  1.15k|      SHA2_32_F(E, F, G, H, A, B, C, D, W2[52]);
  248|  1.15k|      SHA2_32_F(D, E, F, G, H, A, B, C, W2[53]);
  249|  1.15k|      SHA2_32_F(C, D, E, F, G, H, A, B, W2[54]);
  250|  1.15k|      SHA2_32_F(B, C, D, E, F, G, H, A, W2[55]);
  251|  1.15k|      SHA2_32_F(A, B, C, D, E, F, G, H, W2[56]);
  252|  1.15k|      SHA2_32_F(H, A, B, C, D, E, F, G, W2[57]);
  253|  1.15k|      SHA2_32_F(G, H, A, B, C, D, E, F, W2[58]);
  254|  1.15k|      SHA2_32_F(F, G, H, A, B, C, D, E, W2[59]);
  255|  1.15k|      SHA2_32_F(E, F, G, H, A, B, C, D, W2[60]);
  256|  1.15k|      SHA2_32_F(D, E, F, G, H, A, B, C, W2[61]);
  257|  1.15k|      SHA2_32_F(C, D, E, F, G, H, A, B, W2[62]);
  258|  1.15k|      SHA2_32_F(B, C, D, E, F, G, H, A, W2[63]);
  259|       |
  260|  1.15k|      A = (digest[0] += A);
  261|  1.15k|      B = (digest[1] += B);
  262|  1.15k|      C = (digest[2] += C);
  263|  1.15k|      D = (digest[3] += D);
  264|  1.15k|      E = (digest[4] += E);
  265|  1.15k|      F = (digest[5] += F);
  266|  1.15k|      G = (digest[6] += G);
  267|  1.15k|      H = (digest[7] += H);
  268|  1.15k|   }
  269|       |
  270|   107k|   while(blocks > 0) {
  ------------------
  |  Branch (270:10): [True: 53.7k, False: 54.0k]
  ------------------
  271|  53.7k|      SIMD_4x32 WS[4];
  272|       |
  273|   268k|      for(size_t i = 0; i < 4; i++) {
  ------------------
  |  Branch (273:25): [True: 215k, False: 53.7k]
  ------------------
  274|   215k|         WS[i] = SIMD_4x32::load_be(&data[16 * i]);
  275|   215k|         auto WK = WS[i] + SIMD_4x32::load_le(&SHA256_K[4 * i]);
  276|   215k|         WK.store_le(&W[4 * i]);
  277|   215k|      }
  278|       |
  279|  53.7k|      data += 64;
  280|  53.7k|      blocks -= 1;
  281|       |
  282|   215k|      for(size_t r = 0; r != 48; r += 16) {
  ------------------
  |  Branch (282:25): [True: 161k, False: 53.7k]
  ------------------
  283|   161k|         auto w = next_w(WS) + SIMD_4x32::load_le(&SHA256_K[r + 16]);
  284|       |
  285|   161k|         SHA2_32_F(A, B, C, D, E, F, G, H, W[0]);
  286|   161k|         SHA2_32_F(H, A, B, C, D, E, F, G, W[1]);
  287|   161k|         SHA2_32_F(G, H, A, B, C, D, E, F, W[2]);
  288|   161k|         SHA2_32_F(F, G, H, A, B, C, D, E, W[3]);
  289|       |
  290|   161k|         w.store_le(&W[0]);
  291|       |
  292|   161k|         w = next_w(WS) + SIMD_4x32::load_le(&SHA256_K[r + 20]);
  293|       |
  294|   161k|         SHA2_32_F(E, F, G, H, A, B, C, D, W[4]);
  295|   161k|         SHA2_32_F(D, E, F, G, H, A, B, C, W[5]);
  296|   161k|         SHA2_32_F(C, D, E, F, G, H, A, B, W[6]);
  297|   161k|         SHA2_32_F(B, C, D, E, F, G, H, A, W[7]);
  298|       |
  299|   161k|         w.store_le(&W[4]);
  300|       |
  301|   161k|         w = next_w(WS) + SIMD_4x32::load_le(&SHA256_K[r + 24]);
  302|       |
  303|   161k|         SHA2_32_F(A, B, C, D, E, F, G, H, W[8]);
  304|   161k|         SHA2_32_F(H, A, B, C, D, E, F, G, W[9]);
  305|   161k|         SHA2_32_F(G, H, A, B, C, D, E, F, W[10]);
  306|   161k|         SHA2_32_F(F, G, H, A, B, C, D, E, W[11]);
  307|       |
  308|   161k|         w.store_le(&W[8]);
  309|       |
  310|   161k|         w = next_w(WS) + SIMD_4x32::load_le(&SHA256_K[r + 28]);
  311|       |
  312|   161k|         SHA2_32_F(E, F, G, H, A, B, C, D, W[12]);
  313|   161k|         SHA2_32_F(D, E, F, G, H, A, B, C, W[13]);
  314|   161k|         SHA2_32_F(C, D, E, F, G, H, A, B, W[14]);
  315|   161k|         SHA2_32_F(B, C, D, E, F, G, H, A, W[15]);
  316|       |
  317|   161k|         w.store_le(&W[12]);
  318|   161k|      }
  319|       |
  320|  53.7k|      SHA2_32_F(A, B, C, D, E, F, G, H, W[0]);
  321|  53.7k|      SHA2_32_F(H, A, B, C, D, E, F, G, W[1]);
  322|  53.7k|      SHA2_32_F(G, H, A, B, C, D, E, F, W[2]);
  323|  53.7k|      SHA2_32_F(F, G, H, A, B, C, D, E, W[3]);
  324|  53.7k|      SHA2_32_F(E, F, G, H, A, B, C, D, W[4]);
  325|  53.7k|      SHA2_32_F(D, E, F, G, H, A, B, C, W[5]);
  326|  53.7k|      SHA2_32_F(C, D, E, F, G, H, A, B, W[6]);
  327|  53.7k|      SHA2_32_F(B, C, D, E, F, G, H, A, W[7]);
  328|  53.7k|      SHA2_32_F(A, B, C, D, E, F, G, H, W[8]);
  329|  53.7k|      SHA2_32_F(H, A, B, C, D, E, F, G, W[9]);
  330|  53.7k|      SHA2_32_F(G, H, A, B, C, D, E, F, W[10]);
  331|  53.7k|      SHA2_32_F(F, G, H, A, B, C, D, E, W[11]);
  332|  53.7k|      SHA2_32_F(E, F, G, H, A, B, C, D, W[12]);
  333|  53.7k|      SHA2_32_F(D, E, F, G, H, A, B, C, W[13]);
  334|  53.7k|      SHA2_32_F(C, D, E, F, G, H, A, B, W[14]);
  335|  53.7k|      SHA2_32_F(B, C, D, E, F, G, H, A, W[15]);
  336|       |
  337|  53.7k|      A = (digest[0] += A);
  338|  53.7k|      B = (digest[1] += B);
  339|  53.7k|      C = (digest[2] += C);
  340|  53.7k|      D = (digest[3] += D);
  341|  53.7k|      E = (digest[4] += E);
  342|  53.7k|      F = (digest[5] += F);
  343|  53.7k|      G = (digest[6] += G);
  344|  53.7k|      H = (digest[7] += H);
  345|  53.7k|   }
  346|  54.0k|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_16next_wINS_9SIMD_8x32EEET_PS3_:
   50|  13.8k|BOTAN_FN_ISA_AVX2_BMI2 BOTAN_FORCE_INLINE SIMD_T next_w(SIMD_T x[4]) {
   51|  13.8k|   constexpr size_t sigma0_0 = 7;
   52|  13.8k|   constexpr size_t sigma0_1 = 18;
   53|  13.8k|   constexpr size_t sigma0_2 = 3;
   54|  13.8k|   constexpr size_t sigma1_0 = 17;
   55|  13.8k|   constexpr size_t sigma1_1 = 19;
   56|  13.8k|   constexpr size_t sigma1_2 = 10;
   57|       |
   58|  13.8k|   const SIMD_T lo_mask = SIMD_T(0x03020100, 0x0b0a0908, 0x80808080, 0x80808080);
   59|  13.8k|   const SIMD_T hi_mask = SIMD_T(0x80808080, 0x80808080, 0x03020100, 0x0b0a0908);
   60|       |
   61|  13.8k|   auto t0 = alignr4(x[1], x[0]);
   62|  13.8k|   x[0] += alignr4(x[3], x[2]);
   63|       |
   64|  13.8k|   auto t1 = t0.template shl<32 - sigma0_1>();
   65|  13.8k|   auto t2 = t0.template shr<sigma0_0>();
   66|  13.8k|   auto t3 = t0.template shr<sigma0_2>();
   67|  13.8k|   t0 = t3 ^ t2;
   68|       |
   69|  13.8k|   t3 = shuffle_32<0b11111010>(x[3]);
   70|  13.8k|   t2 = t2.template shr<sigma0_1 - sigma0_0>();
   71|  13.8k|   t0 ^= t1 ^ t2;
   72|  13.8k|   t1 = t1.template shl<sigma0_1 - sigma0_0>();
   73|  13.8k|   t2 = t3.template shr<sigma1_2>();
   74|  13.8k|   t3 = shr64<sigma1_0>(t3);
   75|  13.8k|   x[0] += t0 ^ t1;
   76|       |
   77|  13.8k|   t2 ^= t3;
   78|  13.8k|   t3 = shr64<sigma1_1 - sigma1_0>(t3);
   79|  13.8k|   x[0] += SIMD_T::byte_shuffle(t2 ^ t3, lo_mask);
   80|       |
   81|  13.8k|   t3 = shuffle_32<0b01010000>(x[0]);
   82|  13.8k|   t2 = t3.template shr<sigma1_2>();
   83|  13.8k|   t3 = shr64<sigma1_0>(t3);
   84|  13.8k|   t2 ^= t3;
   85|  13.8k|   t3 = shr64<sigma1_1 - sigma1_0>(t3);
   86|  13.8k|   x[0] += SIMD_T::byte_shuffle(t2 ^ t3, hi_mask);
   87|       |
   88|  13.8k|   const auto tmp = x[0];
   89|  13.8k|   x[0] = x[1];
   90|  13.8k|   x[1] = x[2];
   91|  13.8k|   x[2] = x[3];
   92|  13.8k|   x[3] = tmp;
   93|       |
   94|  13.8k|   return x[3];
   95|  13.8k|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_17alignr4ERKNS_9SIMD_8x32ES3_:
   35|  27.6k|BOTAN_FN_ISA_AVX2_BMI2 inline SIMD_8x32 alignr4(const SIMD_8x32& a, const SIMD_8x32& b) {
   36|       |   return SIMD_8x32(_mm256_alignr_epi8(a.raw(), b.raw(), 4));
   37|  27.6k|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_110shuffle_32ILh250EEENS_9SIMD_8x32ERKS2_:
   45|  13.8k|BOTAN_FN_ISA_AVX2_BMI2 inline SIMD_8x32 shuffle_32(const SIMD_8x32& a) {
   46|       |   return SIMD_8x32(_mm256_shuffle_epi32(a.raw(), S));
   47|  13.8k|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_15shr64ILm17EEENS_9SIMD_8x32ERKS2_:
   40|  27.6k|BOTAN_FN_ISA_AVX2_BMI2 inline SIMD_8x32 shr64(const SIMD_8x32& a) {
   41|  27.6k|   return SIMD_8x32(_mm256_srli_epi64(a.raw(), S));
   42|  27.6k|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_15shr64ILm2EEENS_9SIMD_8x32ERKS2_:
   40|  27.6k|BOTAN_FN_ISA_AVX2_BMI2 inline SIMD_8x32 shr64(const SIMD_8x32& a) {
   41|  27.6k|   return SIMD_8x32(_mm256_srli_epi64(a.raw(), S));
   42|  27.6k|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_110shuffle_32ILh80EEENS_9SIMD_8x32ERKS2_:
   45|  13.8k|BOTAN_FN_ISA_AVX2_BMI2 inline SIMD_8x32 shuffle_32(const SIMD_8x32& a) {
   46|       |   return SIMD_8x32(_mm256_shuffle_epi32(a.raw(), S));
   47|  13.8k|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_16next_wINS_9SIMD_4x32EEET_PS3_:
   50|   645k|BOTAN_FN_ISA_AVX2_BMI2 BOTAN_FORCE_INLINE SIMD_T next_w(SIMD_T x[4]) {
   51|   645k|   constexpr size_t sigma0_0 = 7;
   52|   645k|   constexpr size_t sigma0_1 = 18;
   53|   645k|   constexpr size_t sigma0_2 = 3;
   54|   645k|   constexpr size_t sigma1_0 = 17;
   55|   645k|   constexpr size_t sigma1_1 = 19;
   56|   645k|   constexpr size_t sigma1_2 = 10;
   57|       |
   58|   645k|   const SIMD_T lo_mask = SIMD_T(0x03020100, 0x0b0a0908, 0x80808080, 0x80808080);
   59|   645k|   const SIMD_T hi_mask = SIMD_T(0x80808080, 0x80808080, 0x03020100, 0x0b0a0908);
   60|       |
   61|   645k|   auto t0 = alignr4(x[1], x[0]);
   62|   645k|   x[0] += alignr4(x[3], x[2]);
   63|       |
   64|   645k|   auto t1 = t0.template shl<32 - sigma0_1>();
   65|   645k|   auto t2 = t0.template shr<sigma0_0>();
   66|   645k|   auto t3 = t0.template shr<sigma0_2>();
   67|   645k|   t0 = t3 ^ t2;
   68|       |
   69|   645k|   t3 = shuffle_32<0b11111010>(x[3]);
   70|   645k|   t2 = t2.template shr<sigma0_1 - sigma0_0>();
   71|   645k|   t0 ^= t1 ^ t2;
   72|   645k|   t1 = t1.template shl<sigma0_1 - sigma0_0>();
   73|   645k|   t2 = t3.template shr<sigma1_2>();
   74|   645k|   t3 = shr64<sigma1_0>(t3);
   75|   645k|   x[0] += t0 ^ t1;
   76|       |
   77|   645k|   t2 ^= t3;
   78|   645k|   t3 = shr64<sigma1_1 - sigma1_0>(t3);
   79|   645k|   x[0] += SIMD_T::byte_shuffle(t2 ^ t3, lo_mask);
   80|       |
   81|   645k|   t3 = shuffle_32<0b01010000>(x[0]);
   82|   645k|   t2 = t3.template shr<sigma1_2>();
   83|   645k|   t3 = shr64<sigma1_0>(t3);
   84|   645k|   t2 ^= t3;
   85|   645k|   t3 = shr64<sigma1_1 - sigma1_0>(t3);
   86|   645k|   x[0] += SIMD_T::byte_shuffle(t2 ^ t3, hi_mask);
   87|       |
   88|   645k|   const auto tmp = x[0];
   89|   645k|   x[0] = x[1];
   90|   645k|   x[1] = x[2];
   91|   645k|   x[2] = x[3];
   92|   645k|   x[3] = tmp;
   93|       |
   94|   645k|   return x[3];
   95|   645k|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_17alignr4ERKNS_9SIMD_4x32ES3_:
   21|  1.29M|BOTAN_FN_ISA_AVX2_BMI2 inline SIMD_4x32 alignr4(const SIMD_4x32& a, const SIMD_4x32& b) {
   22|       |   return SIMD_4x32(_mm_alignr_epi8(a.raw(), b.raw(), 4));
   23|  1.29M|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_110shuffle_32ILh250EEENS_9SIMD_4x32ERKS2_:
   31|   645k|BOTAN_FN_ISA_AVX2_BMI2 inline SIMD_4x32 shuffle_32(const SIMD_4x32& a) {
   32|       |   return SIMD_4x32(_mm_shuffle_epi32(a.raw(), S));
   33|   645k|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_15shr64ILm17EEENS_9SIMD_4x32ERKS2_:
   26|  1.29M|BOTAN_FN_ISA_AVX2_BMI2 inline SIMD_4x32 shr64(const SIMD_4x32& a) {
   27|  1.29M|   return SIMD_4x32(_mm_srli_epi64(a.raw(), S));
   28|  1.29M|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_15shr64ILm2EEENS_9SIMD_4x32ERKS2_:
   26|  1.29M|BOTAN_FN_ISA_AVX2_BMI2 inline SIMD_4x32 shr64(const SIMD_4x32& a) {
   27|  1.29M|   return SIMD_4x32(_mm_srli_epi64(a.raw(), S));
   28|  1.29M|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_110shuffle_32ILh80EEENS_9SIMD_4x32ERKS2_:
   31|   645k|BOTAN_FN_ISA_AVX2_BMI2 inline SIMD_4x32 shuffle_32(const SIMD_4x32& a) {
   32|       |   return SIMD_4x32(_mm_shuffle_epi32(a.raw(), S));
   33|   645k|}

_ZNK5Botan6BigInt7byte_atEm:
  117|     32|uint8_t BigInt::byte_at(size_t n) const {
  118|     32|   return get_byte_var(sizeof(word) - (n % sizeof(word)) - 1, word_at(n / sizeof(word)));
  119|     32|}
_ZNK5Botan6BigInt8cmp_wordEm:
  121|  1.96k|int32_t BigInt::cmp_word(word other) const {
  122|  1.96k|   if(signum() < 0) {
  ------------------
  |  Branch (122:7): [True: 1.31k, False: 655]
  ------------------
  123|  1.31k|      return -1;  // other is positive ...
  124|  1.31k|   }
  125|       |
  126|    655|   const size_t sw = this->sig_words();
  127|    655|   if(sw > 1) {
  ------------------
  |  Branch (127:7): [True: 6, False: 649]
  ------------------
  128|      6|      return 1;  // must be larger since other is just one word ...
  129|      6|   }
  130|       |
  131|    649|   return bigint_cmp(this->_data(), sw, &other, 1);
  132|    655|}
_ZN5Botan6BigInt4Data11set_to_zeroEv:
  190|  3.10k|void BigInt::Data::set_to_zero() {
  191|  3.10k|   m_reg.resize(m_reg.capacity());
  192|  3.10k|   clear_mem(m_reg.data(), m_reg.size());
  193|  3.10k|   m_sig_words = 0;
  194|  3.10k|}
_ZNK5Botan6BigInt4Data14calc_sig_wordsEv:
  214|  3.10k|size_t BigInt::Data::calc_sig_words() const {
  215|  3.10k|   const size_t sz = m_reg.size();
  216|  3.10k|   size_t sig = sz;
  217|       |
  218|  3.10k|   word sub = 1;
  219|       |
  220|  27.9k|   for(size_t i = 0; i != sz; ++i) {
  ------------------
  |  Branch (220:22): [True: 24.8k, False: 3.10k]
  ------------------
  221|  24.8k|      const word w = m_reg[sz - i - 1];
  222|  24.8k|      sub &= ct_is_zero(w);
  223|  24.8k|      sig -= sub;
  224|  24.8k|   }
  225|       |
  226|       |   /*
  227|       |   * This depends on the data so is poisoned, but unpoison it here as
  228|       |   * later conditionals are made on the size.
  229|       |   */
  230|  3.10k|   CT::unpoison(sig);
  231|       |
  232|  3.10k|   return sig;
  233|  3.10k|}
_ZNK5Botan6BigInt5bytesEv:
  293|  5.90k|size_t BigInt::bytes() const {
  294|  5.90k|   return round_up(bits(), 8) / 8;
  295|  5.90k|}
_ZNK5Botan6BigInt13top_bits_freeEv:
  297|  5.90k|size_t BigInt::top_bits_free() const {
  298|  5.90k|   const size_t words = sig_words();
  299|       |
  300|  5.90k|   const word top_word = word_at(words - 1);
  301|  5.90k|   const size_t bits_used = high_bit(CT::value_barrier(top_word));
  302|  5.90k|   CT::unpoison(bits_used);
  303|  5.90k|   return WordInfo<word>::bits - bits_used;
  304|  5.90k|}
_ZNK5Botan6BigInt4bitsEv:
  306|  5.90k|size_t BigInt::bits() const {
  307|  5.90k|   const size_t words = sig_words();
  308|       |
  309|  5.90k|   if(words == 0) {
  ------------------
  |  Branch (309:7): [True: 2, False: 5.90k]
  ------------------
  310|      2|      return 0;
  311|      2|   }
  312|       |
  313|  5.90k|   const size_t full_words = (words - 1) * WordInfo<word>::bits;
  314|  5.90k|   const size_t top_bits = WordInfo<word>::bits - top_bits_free();
  315|       |
  316|  5.90k|   return full_words + top_bits;
  317|  5.90k|}
_ZNK5Botan6BigInt12serialize_toENSt3__14spanIhLm18446744073709551615EEE:
  394|  2.95k|void BigInt::serialize_to(std::span<uint8_t> output) const {
  395|  2.95k|   BOTAN_ARG_CHECK(this->bytes() <= output.size(), "Insufficient output space");
  ------------------
  |  |   35|  2.95k|   do {                                                          \
  |  |   36|  2.95k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  2.95k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 2.95k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  2.95k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 2.95k]
  |  |  ------------------
  ------------------
  396|       |
  397|  2.95k|   this->binary_encode(output.data(), output.size());
  398|  2.95k|}
_ZNK5Botan6BigInt13binary_encodeEPhm:
  403|  2.95k|void BigInt::binary_encode(uint8_t output[], size_t len) const {
  404|  2.95k|   const size_t full_words = len / sizeof(word);
  405|  2.95k|   const size_t extra_bytes = len % sizeof(word);
  406|       |
  407|  3.19k|   for(size_t i = 0; i != full_words; ++i) {
  ------------------
  |  Branch (407:22): [True: 241, False: 2.95k]
  ------------------
  408|    241|      const word w = word_at(i);
  409|    241|      store_be(w, output + (len - (i + 1) * sizeof(word)));
  410|    241|   }
  411|       |
  412|  2.95k|   if(extra_bytes > 0) {
  ------------------
  |  Branch (412:7): [True: 2.94k, False: 7]
  ------------------
  413|  2.94k|      const word w = word_at(full_words);
  414|       |
  415|  7.86k|      for(size_t i = 0; i != extra_bytes; ++i) {
  ------------------
  |  Branch (415:25): [True: 4.92k, False: 2.94k]
  ------------------
  416|  4.92k|         output[extra_bytes - i - 1] = get_byte_var(sizeof(word) - i - 1, w);
  417|  4.92k|      }
  418|  2.94k|   }
  419|  2.95k|}
_ZN5Botan6BigInt17assign_from_bytesENSt3__14spanIKhLm18446744073709551615EEE:
  424|  3.10k|void BigInt::assign_from_bytes(std::span<const uint8_t> bytes) {
  425|  3.10k|   clear();
  426|       |
  427|  3.10k|   const size_t length = bytes.size();
  428|  3.10k|   const size_t full_words = length / sizeof(word);
  429|  3.10k|   const size_t extra_bytes = length % sizeof(word);
  430|       |
  431|  3.10k|   secure_vector<word> reg((round_up(full_words + (extra_bytes > 0 ? 1 : 0), 8)));
  ------------------
  |  Branch (431:52): [True: 3.08k, False: 12]
  ------------------
  432|       |
  433|  3.35k|   for(size_t i = 0; i != full_words; ++i) {
  ------------------
  |  Branch (433:22): [True: 252, False: 3.10k]
  ------------------
  434|    252|      reg[i] = load_be<word>(bytes.last<sizeof(word)>());
  435|    252|      bytes = bytes.first(bytes.size() - sizeof(word));
  436|    252|   }
  437|       |
  438|  3.10k|   if(!bytes.empty()) {
  ------------------
  |  Branch (438:7): [True: 3.08k, False: 12]
  ------------------
  439|  3.08k|      BOTAN_ASSERT_NOMSG(extra_bytes == bytes.size());
  ------------------
  |  |   84|  3.08k|   do {                                                                     \
  |  |   85|  3.08k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  3.08k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 3.08k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  3.08k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 3.08k]
  |  |  ------------------
  ------------------
  440|  3.08k|      std::array<uint8_t, sizeof(word)> last_partial_word = {0};
  441|  3.08k|      copy_mem(std::span{last_partial_word}.last(extra_bytes), bytes);
  442|  3.08k|      reg[full_words] = load_be<word>(last_partial_word);
  443|  3.08k|   }
  444|       |
  445|  3.10k|   m_data.swap(reg);
  446|  3.10k|}
_ZNK5Botan6BigInt20_const_time_unpoisonEv:
  558|  5.16k|void BigInt::_const_time_unpoison() const {
  559|  5.16k|   CT::unpoison(m_data.const_data(), m_data.size());
  560|  5.16k|}

_ZN5Botan8PEM_Code6decodeERNS_10DataSourceERNSt3__112basic_stringIcNS3_11char_traitsIcEENS3_9allocatorIcEEEE:
   64|    199|secure_vector<uint8_t> decode(DataSource& source, std::string& label) {
   65|    199|   const size_t RANDOM_CHAR_LIMIT = 8;
   66|       |
   67|    199|   label.clear();
   68|       |
   69|    199|   const std::string PEM_HEADER1 = "-----BEGIN ";
   70|    199|   const std::string PEM_HEADER2 = "-----";
   71|    199|   size_t position = 0;
   72|       |
   73|  5.97k|   while(position != PEM_HEADER1.length()) {
  ------------------
  |  Branch (73:10): [True: 5.81k, False: 167]
  ------------------
   74|  5.81k|      auto b = source.read_byte();
   75|       |
   76|  5.81k|      if(!b) {
  ------------------
  |  Branch (76:10): [True: 31, False: 5.78k]
  ------------------
   77|     31|         throw Decoding_Error("PEM: No PEM header found");
   78|     31|      }
   79|  5.78k|      if(static_cast<char>(*b) == PEM_HEADER1[position]) {
  ------------------
  |  Branch (79:10): [True: 2.26k, False: 3.51k]
  ------------------
   80|  2.26k|         ++position;
   81|  3.51k|      } else if(position >= RANDOM_CHAR_LIMIT) {
  ------------------
  |  Branch (81:17): [True: 1, False: 3.51k]
  ------------------
   82|      1|         throw Decoding_Error("PEM: Malformed PEM header");
   83|  3.51k|      } else {
   84|  3.51k|         position = 0;
   85|  3.51k|      }
   86|  5.78k|   }
   87|    167|   position = 0;
   88|  3.11k|   while(position != PEM_HEADER2.length()) {
  ------------------
  |  Branch (88:10): [True: 2.97k, False: 140]
  ------------------
   89|  2.97k|      auto b = source.read_byte();
   90|       |
   91|  2.97k|      if(!b) {
  ------------------
  |  Branch (91:10): [True: 18, False: 2.95k]
  ------------------
   92|     18|         throw Decoding_Error("PEM: No PEM header found");
   93|     18|      }
   94|  2.95k|      if(static_cast<char>(*b) == PEM_HEADER2[position]) {
  ------------------
  |  Branch (94:10): [True: 718, False: 2.23k]
  ------------------
   95|    718|         ++position;
   96|  2.23k|      } else if(position > 0) {
  ------------------
  |  Branch (96:17): [True: 6, False: 2.23k]
  ------------------
   97|      6|         throw Decoding_Error("PEM: Malformed PEM header");
   98|      6|      }
   99|       |
  100|  2.94k|      if(position == 0) {
  ------------------
  |  Branch (100:10): [True: 2.23k, False: 718]
  ------------------
  101|  2.23k|         if(label.size() >= 128) {
  ------------------
  |  Branch (101:13): [True: 3, False: 2.22k]
  ------------------
  102|      3|            throw Decoding_Error("PEM: Label too long");
  103|      3|         }
  104|  2.22k|         label += static_cast<char>(*b);
  105|  2.22k|      }
  106|  2.94k|   }
  107|       |
  108|    140|   std::vector<char> b64;
  109|       |
  110|    140|   const std::string PEM_TRAILER = fmt("-----END {}-----", label);
  111|    140|   position = 0;
  112|  35.3k|   while(position != PEM_TRAILER.length()) {
  ------------------
  |  Branch (112:10): [True: 35.2k, False: 92]
  ------------------
  113|  35.2k|      auto b = source.read_byte();
  114|       |
  115|  35.2k|      if(!b) {
  ------------------
  |  Branch (115:10): [True: 35, False: 35.2k]
  ------------------
  116|     35|         throw Decoding_Error("PEM: No PEM trailer found");
  117|     35|      }
  118|  35.2k|      if(static_cast<char>(*b) == PEM_TRAILER[position]) {
  ------------------
  |  Branch (118:10): [True: 2.11k, False: 33.1k]
  ------------------
  119|  2.11k|         ++position;
  120|  33.1k|      } else if(position > 0) {
  ------------------
  |  Branch (120:17): [True: 13, False: 33.0k]
  ------------------
  121|     13|         throw Decoding_Error("PEM: Malformed PEM trailer");
  122|     13|      }
  123|       |
  124|  35.2k|      if(position == 0) {
  ------------------
  |  Branch (124:10): [True: 33.0k, False: 2.11k]
  ------------------
  125|  33.0k|         b64.push_back(*b);
  126|  33.0k|      }
  127|  35.2k|   }
  128|       |
  129|     92|   return base64_decode(b64.data(), b64.size());
  130|    140|}
_ZN5Botan8PEM_Code7matchesERNS_10DataSourceENSt3__117basic_string_viewIcNS3_11char_traitsIcEEEEm:
  145|  4.06k|bool matches(DataSource& source, std::string_view extra, size_t search_range) {
  146|  4.06k|   const std::string PEM_HEADER = fmt("-----BEGIN {}", extra);
  147|       |
  148|  4.06k|   std::array<uint8_t, 4096> stack_buf{};
  149|  4.06k|   std::vector<uint8_t> heap_buf;
  150|  4.06k|   uint8_t* search_buf = stack_buf.data();
  151|  4.06k|   if(search_range > stack_buf.size()) {
  ------------------
  |  Branch (151:7): [True: 0, False: 4.06k]
  ------------------
  152|      0|      heap_buf.resize(search_range);
  153|      0|      search_buf = heap_buf.data();
  154|      0|   }
  155|       |
  156|  4.06k|   const size_t got = source.peek(search_buf, search_range, 0);
  157|       |
  158|  4.06k|   if(got < PEM_HEADER.length()) {
  ------------------
  |  Branch (158:7): [True: 328, False: 3.74k]
  ------------------
  159|    328|      return false;
  160|    328|   }
  161|       |
  162|  3.74k|   return std::search(search_buf, search_buf + got, PEM_HEADER.begin(), PEM_HEADER.end()) != search_buf + got;
  163|  4.06k|}

_ZN5Botan15load_public_keyERKNS_19AlgorithmIdentifierENSt3__14spanIKhLm18446744073709551615EEE:
  131|  1.32k|                                            [[maybe_unused]] std::span<const uint8_t> key_bits) {
  132|  1.32k|   const std::string alg_name = [&]() -> std::string {
  133|  1.32k|      if(const auto name = alg_id.oid().registered_name()) {
  134|  1.32k|         const std::vector<std::string> alg_info = split_on(*name, '/');
  135|  1.32k|         if(!alg_info.empty()) {
  136|  1.32k|            return alg_info[0];
  137|  1.32k|         }
  138|  1.32k|      }
  139|       |
  140|  1.32k|      throw Decoding_Error(
  141|  1.32k|         fmt("Public key decoding failed, no algorithm associated with {}", alg_id.oid().to_string()));
  142|  1.32k|   }();
  143|       |
  144|  1.32k|#if defined(BOTAN_HAS_RSA)
  145|  1.32k|   if(alg_name == "RSA") {
  ------------------
  |  Branch (145:7): [True: 0, False: 1.32k]
  ------------------
  146|      0|      return std::make_unique<RSA_PublicKey>(alg_id, key_bits);
  147|      0|   }
  148|  1.32k|#endif
  149|       |
  150|  1.32k|#if defined(BOTAN_HAS_X25519)
  151|  1.32k|   if(alg_name == "X25519" || alg_name == "Curve25519") {
  ------------------
  |  Branch (151:7): [True: 1.32k, False: 0]
  |  Branch (151:31): [True: 0, False: 0]
  ------------------
  152|      0|      return std::make_unique<X25519_PublicKey>(alg_id, key_bits);
  153|      0|   }
  154|  1.32k|#endif
  155|       |
  156|  1.32k|#if defined(BOTAN_HAS_X448)
  157|  1.32k|   if(alg_name == "X448") {
  ------------------
  |  Branch (157:7): [True: 0, False: 1.32k]
  ------------------
  158|      0|      return std::make_unique<X448_PublicKey>(alg_id, key_bits);
  159|      0|   }
  160|  1.32k|#endif
  161|       |
  162|  1.32k|#if defined(BOTAN_HAS_MCELIECE)
  163|  1.32k|   if(alg_name == "McEliece") {
  ------------------
  |  Branch (163:7): [True: 0, False: 1.32k]
  ------------------
  164|      0|      return std::make_unique<McEliece_PublicKey>(alg_id, key_bits);
  165|      0|   }
  166|  1.32k|#endif
  167|       |
  168|  1.32k|#if defined(BOTAN_HAS_FRODOKEM)
  169|  1.32k|   if(alg_name == "FrodoKEM" || alg_name.starts_with("FrodoKEM-") || alg_name.starts_with("eFrodoKEM-")) {
  ------------------
  |  Branch (169:7): [True: 1.32k, False: 0]
  |  Branch (169:33): [True: 0, False: 0]
  |  Branch (169:70): [True: 0, False: 0]
  ------------------
  170|      0|      return std::make_unique<FrodoKEM_PublicKey>(alg_id, key_bits);
  171|      0|   }
  172|  1.32k|#endif
  173|       |
  174|  1.32k|#if defined(BOTAN_HAS_KYBER) || defined(BOTAN_HAS_KYBER_90S)
  175|  1.32k|   if(alg_name == "Kyber" || alg_name.starts_with("Kyber-")) {
  ------------------
  |  Branch (175:7): [True: 1.32k, False: 0]
  |  Branch (175:30): [True: 0, False: 0]
  ------------------
  176|      0|      return std::make_unique<Kyber_PublicKey>(alg_id, key_bits);
  177|      0|   }
  178|  1.32k|#endif
  179|       |
  180|  1.32k|#if defined(BOTAN_HAS_ML_KEM)
  181|  1.32k|   if(alg_name.starts_with("ML-KEM-")) {
  ------------------
  |  Branch (181:7): [True: 0, False: 1.32k]
  ------------------
  182|      0|      return std::make_unique<ML_KEM_PublicKey>(alg_id, key_bits);
  183|      0|   }
  184|  1.32k|#endif
  185|       |
  186|  1.32k|#if defined(BOTAN_HAS_ECDSA)
  187|  1.32k|   if(alg_name == "ECDSA") {
  ------------------
  |  Branch (187:7): [True: 0, False: 1.32k]
  ------------------
  188|      0|      return std::make_unique<ECDSA_PublicKey>(alg_id, key_bits);
  189|      0|   }
  190|  1.32k|#endif
  191|       |
  192|  1.32k|#if defined(BOTAN_HAS_ECDH)
  193|  1.32k|   if(alg_name == "ECDH") {
  ------------------
  |  Branch (193:7): [True: 0, False: 1.32k]
  ------------------
  194|      0|      return std::make_unique<ECDH_PublicKey>(alg_id, key_bits);
  195|      0|   }
  196|  1.32k|#endif
  197|       |
  198|  1.32k|#if defined(BOTAN_HAS_DIFFIE_HELLMAN)
  199|  1.32k|   if(alg_name == "DH") {
  ------------------
  |  Branch (199:7): [True: 0, False: 1.32k]
  ------------------
  200|      0|      return std::make_unique<DH_PublicKey>(alg_id, key_bits);
  201|      0|   }
  202|  1.32k|#endif
  203|       |
  204|  1.32k|#if defined(BOTAN_HAS_DSA)
  205|  1.32k|   if(alg_name == "DSA") {
  ------------------
  |  Branch (205:7): [True: 0, False: 1.32k]
  ------------------
  206|      0|      return std::make_unique<DSA_PublicKey>(alg_id, key_bits);
  207|      0|   }
  208|  1.32k|#endif
  209|       |
  210|  1.32k|#if defined(BOTAN_HAS_ELGAMAL)
  211|  1.32k|   if(alg_name == "ElGamal") {
  ------------------
  |  Branch (211:7): [True: 0, False: 1.32k]
  ------------------
  212|      0|      return std::make_unique<ElGamal_PublicKey>(alg_id, key_bits);
  213|      0|   }
  214|  1.32k|#endif
  215|       |
  216|  1.32k|#if defined(BOTAN_HAS_ECGDSA)
  217|  1.32k|   if(alg_name == "ECGDSA") {
  ------------------
  |  Branch (217:7): [True: 0, False: 1.32k]
  ------------------
  218|      0|      return std::make_unique<ECGDSA_PublicKey>(alg_id, key_bits);
  219|      0|   }
  220|  1.32k|#endif
  221|       |
  222|  1.32k|#if defined(BOTAN_HAS_ECKCDSA)
  223|  1.32k|   if(alg_name == "ECKCDSA") {
  ------------------
  |  Branch (223:7): [True: 0, False: 1.32k]
  ------------------
  224|      0|      return std::make_unique<ECKCDSA_PublicKey>(alg_id, key_bits);
  225|      0|   }
  226|  1.32k|#endif
  227|       |
  228|  1.32k|#if defined(BOTAN_HAS_ED25519)
  229|  1.32k|   if(alg_name == "Ed25519") {
  ------------------
  |  Branch (229:7): [True: 0, False: 1.32k]
  ------------------
  230|      0|      return std::make_unique<Ed25519_PublicKey>(alg_id, key_bits);
  231|      0|   }
  232|  1.32k|#endif
  233|       |
  234|  1.32k|#if defined(BOTAN_HAS_ED448)
  235|  1.32k|   if(alg_name == "Ed448") {
  ------------------
  |  Branch (235:7): [True: 0, False: 1.32k]
  ------------------
  236|      0|      return std::make_unique<Ed448_PublicKey>(alg_id, key_bits);
  237|      0|   }
  238|  1.32k|#endif
  239|       |
  240|  1.32k|#if defined(BOTAN_HAS_GOST_34_10_2001)
  241|  1.32k|   if(alg_name == "GOST-34.10" || alg_name == "GOST-34.10-2012-256" || alg_name == "GOST-34.10-2012-512") {
  ------------------
  |  Branch (241:7): [True: 1.32k, False: 0]
  |  Branch (241:35): [True: 0, False: 0]
  |  Branch (241:72): [True: 0, False: 0]
  ------------------
  242|      0|      return std::make_unique<GOST_3410_PublicKey>(alg_id, key_bits);
  243|      0|   }
  244|  1.32k|#endif
  245|       |
  246|  1.32k|#if defined(BOTAN_HAS_SM2)
  247|  1.32k|   if(alg_name == "SM2" || alg_name == "SM2_Sig" || alg_name == "SM2_Enc") {
  ------------------
  |  Branch (247:7): [True: 1.32k, False: 0]
  |  Branch (247:28): [True: 0, False: 0]
  |  Branch (247:53): [True: 0, False: 0]
  ------------------
  248|      0|      return std::make_unique<SM2_PublicKey>(alg_id, key_bits);
  249|      0|   }
  250|  1.32k|#endif
  251|       |
  252|  1.32k|#if defined(BOTAN_HAS_XMSS_RFC8391)
  253|  1.32k|   if(alg_name == "XMSS") {
  ------------------
  |  Branch (253:7): [True: 0, False: 1.32k]
  ------------------
  254|      0|      return std::make_unique<XMSS_PublicKey>(alg_id, key_bits);
  255|      0|   }
  256|  1.32k|#endif
  257|       |
  258|  1.32k|#if defined(BOTAN_HAS_DILITHIUM) || defined(BOTAN_HAS_DILITHIUM_AES)
  259|  1.32k|   if(alg_name == "Dilithium" || alg_name.starts_with("Dilithium-")) {
  ------------------
  |  Branch (259:7): [True: 1.32k, False: 0]
  |  Branch (259:34): [True: 0, False: 0]
  ------------------
  260|      0|      return std::make_unique<Dilithium_PublicKey>(alg_id, key_bits);
  261|      0|   }
  262|  1.32k|#endif
  263|       |
  264|  1.32k|#if defined(BOTAN_HAS_ML_DSA)
  265|  1.32k|   if(alg_name.starts_with("ML-DSA-")) {
  ------------------
  |  Branch (265:7): [True: 0, False: 1.32k]
  ------------------
  266|      0|      return std::make_unique<ML_DSA_PublicKey>(alg_id, key_bits);
  267|      0|   }
  268|  1.32k|#endif
  269|       |
  270|  1.32k|#if defined(BOTAN_HAS_HSS_LMS)
  271|  1.32k|   if(alg_name == "HSS-LMS") {
  ------------------
  |  Branch (271:7): [True: 0, False: 1.32k]
  ------------------
  272|      0|      return std::make_unique<HSS_LMS_PublicKey>(alg_id, key_bits);
  273|      0|   }
  274|  1.32k|#endif
  275|       |
  276|  1.32k|#if defined(BOTAN_HAS_SPHINCS_PLUS_WITH_SHA2) || defined(BOTAN_HAS_SPHINCS_PLUS_WITH_SHAKE)
  277|  1.32k|   if(alg_name == "SPHINCS+" || alg_name.starts_with("SphincsPlus-")) {
  ------------------
  |  Branch (277:7): [True: 1.32k, False: 0]
  |  Branch (277:33): [True: 0, False: 0]
  ------------------
  278|      0|      return std::make_unique<SphincsPlus_PublicKey>(alg_id, key_bits);
  279|      0|   }
  280|  1.32k|#endif
  281|       |
  282|  1.32k|#if defined(BOTAN_HAS_SLH_DSA_WITH_SHA2) || defined(BOTAN_HAS_SLH_DSA_WITH_SHAKE)
  283|  1.32k|   if(alg_name.starts_with("SLH-DSA-") || alg_name.starts_with("Hash-SLH-DSA-")) {
  ------------------
  |  Branch (283:7): [True: 1.32k, False: 0]
  |  Branch (283:43): [True: 0, False: 0]
  ------------------
  284|      0|      return std::make_unique<SLH_DSA_PublicKey>(alg_id, key_bits);
  285|      0|   }
  286|  1.32k|#endif
  287|       |
  288|  1.32k|#if defined(BOTAN_HAS_CLASSICMCELIECE)
  289|  1.32k|   if(alg_name.starts_with("ClassicMcEliece")) {
  ------------------
  |  Branch (289:7): [True: 0, False: 1.32k]
  ------------------
  290|      0|      return std::make_unique<Classic_McEliece_PublicKey>(alg_id, key_bits);
  291|      0|   }
  292|  1.32k|#endif
  293|       |
  294|  1.32k|   throw Decoding_Error(fmt("Unknown or unavailable public key algorithm '{}'", alg_name));
  295|  1.32k|}
pk_algs.cpp:_ZZN5Botan15load_public_keyERKNS_19AlgorithmIdentifierENSt3__14spanIKhLm18446744073709551615EEEENK3$_0clEv:
  132|  1.32k|   const std::string alg_name = [&]() -> std::string {
  133|  1.32k|      if(const auto name = alg_id.oid().registered_name()) {
  ------------------
  |  Branch (133:21): [True: 0, False: 1.32k]
  ------------------
  134|      0|         const std::vector<std::string> alg_info = split_on(*name, '/');
  135|      0|         if(!alg_info.empty()) {
  ------------------
  |  Branch (135:13): [True: 0, False: 0]
  ------------------
  136|      0|            return alg_info[0];
  137|      0|         }
  138|      0|      }
  139|       |
  140|  1.32k|      throw Decoding_Error(
  141|  1.32k|         fmt("Public key decoding failed, no algorithm associated with {}", alg_id.oid().to_string()));
  142|  1.32k|   }();

_ZN5Botan22format_hex_fingerprintENSt3__14spanIKhLm18446744073709551615EEE:
   47|  2.64k|std::string format_hex_fingerprint(std::span<const uint8_t> bits) {
   48|  2.64k|   const std::string hex = hex_encode(bits);
   49|       |
   50|  2.64k|   std::string fprint;
   51|  2.64k|   fprint.reserve(3 * bits.size());
   52|       |
   53|  71.3k|   for(size_t i = 0; i != hex.size(); i += 2) {
  ------------------
  |  Branch (53:22): [True: 68.6k, False: 2.64k]
  ------------------
   54|  68.6k|      if(i != 0) {
  ------------------
  |  Branch (54:10): [True: 66.0k, False: 2.64k]
  ------------------
   55|  66.0k|         fprint.push_back(':');
   56|  66.0k|      }
   57|       |
   58|  68.6k|      fprint.push_back(hex[i]);
   59|  68.6k|      fprint.push_back(hex[i + 1]);
   60|  68.6k|   }
   61|       |
   62|  2.64k|   return fprint;
   63|  2.64k|}

_ZN5Botan4X5098load_keyERNS_10DataSourceE:
   28|  1.32k|std::unique_ptr<Public_Key> load_key(DataSource& source) {
   29|  1.32k|   try {
   30|  1.32k|      AlgorithmIdentifier alg_id;
   31|  1.32k|      std::vector<uint8_t> key_bits;
   32|       |
   33|  1.32k|      if(ASN1::maybe_BER(source) && !PEM_Code::matches(source)) {
  ------------------
  |  Branch (33:10): [True: 1.32k, False: 0]
  |  Branch (33:37): [True: 1.32k, False: 0]
  ------------------
   34|  1.32k|         BER_Decoder(source, BER_Decoder::Limits::DER())
   35|  1.32k|            .start_sequence()
   36|  1.32k|            .decode(alg_id)
   37|  1.32k|            .decode_octet_aligned_bitstring(key_bits)
   38|  1.32k|            .end_cons()
   39|  1.32k|            .verify_end();
   40|  1.32k|      } else {
   41|      0|         DataSource_Memory ber(PEM_Code::decode_check_label(source, "PUBLIC KEY"));
   42|       |
   43|      0|         BER_Decoder(ber, BER_Decoder::Limits::DER())
   44|      0|            .start_sequence()
   45|      0|            .decode(alg_id)
   46|      0|            .decode_octet_aligned_bitstring(key_bits)
   47|      0|            .end_cons()
   48|      0|            .verify_end();
   49|      0|      }
   50|       |
   51|  1.32k|      if(key_bits.empty()) {
  ------------------
  |  Branch (51:10): [True: 0, False: 1.32k]
  ------------------
   52|      0|         throw Decoding_Error("X.509 public key decoding");
   53|      0|      }
   54|       |
   55|  1.32k|      return load_public_key(alg_id, key_bits);
   56|  1.32k|   } catch(Decoding_Error& e) {
   57|  1.32k|      throw Decoding_Error("X.509 public key decoding", e);
   58|  1.32k|   }
   59|  1.32k|}

_ZN5Botan3TLS18Certificate_VerifyC2ENSt3__14spanIKhLm18446744073709551615EEE:
   20|  2.50k|Certificate_Verify::Certificate_Verify(std::span<const uint8_t> buf) {
   21|  2.50k|   TLS_Data_Reader reader("CertificateVerify", buf);
   22|       |
   23|  2.50k|   m_scheme = Signature_Scheme(reader.get_uint16_t());
   24|       |   // Somewhat oddly, the signature really is allowed to be empty in a CertificateVerify
   25|  2.50k|   m_signature = reader.get_range<uint8_t>(2, 0, 65535);
   26|  2.50k|   reader.assert_done();
   27|       |
   28|  2.50k|   if(!m_scheme.is_set()) {
  ------------------
  |  Branch (28:7): [True: 4, False: 2.49k]
  ------------------
   29|      4|      throw Decoding_Error("Counterparty did not send hash/sig IDS");
   30|      4|   }
   31|  2.50k|}

_ZN5Botan3TLS21Client_Hello_InternalC2ENSt3__14spanIKhLm18446744073709551615EEE:
   46|  6.01k|Client_Hello_Internal::Client_Hello_Internal(std::span<const uint8_t> buf) {
   47|       |   /*
   48|       |   Minimum possible client hello
   49|       |
   50|       |   version: 2 bytes
   51|       |   random: 32 bytes
   52|       |   session_id len: 1 byte
   53|       |   ciphersuite_len: 2
   54|       |   ciphersuite (single): 2
   55|       |   compression_len: 1
   56|       |   compression (single): 1
   57|       |   */
   58|       |
   59|  6.01k|   constexpr size_t MinimumClientHelloBytes = 2 + 32 + 1 + 2 + 2 + 1 + 1;
   60|  6.01k|   if(buf.size() < MinimumClientHelloBytes) {
  ------------------
  |  Branch (60:7): [True: 18, False: 6.00k]
  ------------------
   61|     18|      throw Decoding_Error("Client_Hello: Packet corrupted");
   62|     18|   }
   63|       |
   64|  6.00k|   TLS_Data_Reader reader("ClientHello", buf);
   65|       |
   66|  6.00k|   const uint8_t major_version = reader.get_byte();
   67|  6.00k|   const uint8_t minor_version = reader.get_byte();
   68|       |
   69|  6.00k|   m_legacy_version = Protocol_Version(major_version, minor_version);
   70|       |
   71|       |   // DTLS has an additional 1 byte cookie length field
   72|  6.00k|   if(m_legacy_version.is_datagram_protocol() && buf.size() < MinimumClientHelloBytes + 1) {
  ------------------
  |  Branch (72:7): [True: 2.66k, False: 3.33k]
  |  Branch (72:50): [True: 2, False: 2.66k]
  ------------------
   73|      2|      throw Decoding_Error("Client_Hello: DTLS packet corrupted");
   74|      2|   }
   75|       |
   76|  5.99k|   m_random = reader.get_fixed<uint8_t>(32);
   77|  5.99k|   m_session_id = Session_ID(reader.get_range<uint8_t>(1, 0, 32));
   78|       |
   79|  5.99k|   if(m_legacy_version.is_datagram_protocol()) {
  ------------------
  |  Branch (79:7): [True: 2.65k, False: 3.34k]
  ------------------
   80|  2.65k|      auto sha256 = HashFunction::create_or_throw("SHA-256");
   81|  2.65k|      sha256->update(reader.get_data_read_so_far());
   82|       |
   83|  2.65k|      m_hello_cookie = reader.get_range<uint8_t>(1, 0, 255);
   84|       |
   85|  2.65k|      sha256->update(reader.get_remaining());
   86|  2.65k|      m_cookie_input_bits = sha256->final_stdvec();
   87|  2.65k|   }
   88|       |
   89|  5.99k|   m_suites = reader.get_range_vector<uint16_t>(2, 1, 32767);
   90|  5.99k|   m_comp_methods = reader.get_range_vector<uint8_t>(1, 1, 255);
   91|       |
   92|  5.99k|   m_extensions.deserialize(reader, Connection_Side::Client, Handshake_Type::ClientHello);
   93|  5.99k|}
_ZNK5Botan3TLS21Client_Hello_Internal7versionEv:
   95|  5.55k|Protocol_Version Client_Hello_Internal::version() const {
   96|       |   // RFC 8446 4.2.1
   97|       |   //    If [the "supported_versions"] extension is not present, servers
   98|       |   //    which are compliant with this specification and which also support
   99|       |   //    TLS 1.2 MUST negotiate TLS 1.2 or prior as specified in [RFC5246],
  100|       |   //    even if ClientHello.legacy_version is 0x0304 or later.
  101|       |   //
  102|       |   // RFC 8446 4.2.1
  103|       |   //    Servers MUST be prepared to receive ClientHellos that include
  104|       |   //    [the supported_versions] extension but do not include 0x0304 in
  105|       |   //    the list of versions.
  106|       |   //
  107|       |   // RFC 8446 4.1.2
  108|       |   //    TLS 1.3 ClientHellos are identified as having a legacy_version of
  109|       |   //    0x0303 and a supported_versions extension present with 0x0304 as
  110|       |   //    the highest version indicated therein.
  111|  5.55k|   if(!extensions().has<Supported_Versions>() ||
  ------------------
  |  Branch (111:7): [True: 4.98k, False: 564]
  ------------------
  112|  5.18k|      !extensions().get<Supported_Versions>()->supports(Protocol_Version::TLS_V13)) {
  ------------------
  |  Branch (112:7): [True: 198, False: 366]
  ------------------
  113|       |      // The exact legacy_version is ignored we just inspect it to
  114|       |      // distinguish TLS and DTLS.
  115|  5.18k|      return (m_legacy_version.is_datagram_protocol()) ? Protocol_Version::DTLS_V12 : Protocol_Version::TLS_V12;
  ------------------
  |  Branch (115:14): [True: 2.48k, False: 2.69k]
  ------------------
  116|  5.18k|   }
  117|       |
  118|       |   // Note: The Client_Hello_13 class will make sure that legacy_version
  119|       |   //       is exactly 0x0303 (aka ossified TLS 1.2)
  120|    366|   return Protocol_Version::TLS_V13;
  121|  5.55k|}
_ZN5Botan3TLS12Client_HelloC2EOS1_:
  123|  21.9k|Client_Hello::Client_Hello(Client_Hello&&) noexcept = default;
_ZN5Botan3TLS12Client_HelloD2Ev:
  126|  27.4k|Client_Hello::~Client_Hello() = default;
_ZN5Botan3TLS12Client_HelloC2ENSt3__110unique_ptrINS0_21Client_Hello_InternalENS2_14default_deleteIS4_EEEE:
  133|  5.55k|Client_Hello::Client_Hello(std::unique_ptr<Client_Hello_Internal> data) : m_data(std::move(data)) {
  134|  5.55k|   BOTAN_ASSERT_NONNULL(m_data);
  ------------------
  |  |  123|  5.55k|   do {                                                                                   \
  |  |  124|  5.55k|      if((ptr) == nullptr) {                                                              \
  |  |  ------------------
  |  |  |  Branch (124:10): [True: 0, False: 5.55k]
  |  |  ------------------
  |  |  125|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                              \
  |  |  126|      0|         Botan::assertion_failure(#ptr " is not null", "", __func__, __FILE__, __LINE__); \
  |  |  127|      0|      }                                                                                   \
  |  |  128|  5.55k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (128:12): [Folded, False: 5.55k]
  |  |  ------------------
  ------------------
  135|  5.55k|}
_ZN5Botan3TLS20Client_Hello_12_ShimC2ENSt3__110unique_ptrINS0_21Client_Hello_InternalENS2_14default_deleteIS4_EEEE:
  288|  5.18k|      Client_Hello(std::move(data)) {}

_ZN5Botan3TLS21Server_Hello_InternalC2ENSt3__14spanIKhLm18446744073709551615EEE:
   48|  4.31k|Server_Hello_Internal::Server_Hello_Internal(std::span<const uint8_t> buf) {
   49|  4.31k|   if(buf.size() < 38) {
  ------------------
  |  Branch (49:7): [True: 19, False: 4.29k]
  ------------------
   50|     19|      throw Decoding_Error("Server_Hello: Packet corrupted");
   51|     19|   }
   52|       |
   53|  4.29k|   TLS_Data_Reader reader("ServerHello", buf);
   54|       |
   55|  4.29k|   const uint8_t major_version = reader.get_byte();
   56|  4.29k|   const uint8_t minor_version = reader.get_byte();
   57|       |
   58|  4.29k|   m_legacy_version = Protocol_Version(major_version, minor_version);
   59|       |
   60|       |   // RFC 8446 4.1.3
   61|       |   //    Upon receiving a message with type server_hello, implementations MUST
   62|       |   //    first examine the Random value and, if it matches this value, process
   63|       |   //    it as described in Section 4.1.4 [Hello Retry Request]).
   64|  4.29k|   m_random = reader.get_fixed<uint8_t>(32);
   65|  4.29k|   m_is_hello_retry_request = CT::is_equal<uint8_t>(m_random, HELLO_RETRY_REQUEST_MARKER).as_bool();
   66|       |
   67|  4.29k|   m_session_id = Session_ID(reader.get_range<uint8_t>(1, 0, 32));
   68|  4.29k|   m_ciphersuite = reader.get_uint16_t();
   69|  4.29k|   m_comp_method = reader.get_byte();
   70|       |
   71|       |   // Note that this code path might parse a TLS 1.2 (or older) server hello message that
   72|       |   // is nevertheless marked as being a 'hello retry request' (potentially maliciously).
   73|       |   // Extension parsing will however not be affected by the associated flag.
   74|       |   // Only after parsing the extensions will the upstream code be able to decide
   75|       |   // whether we're dealing with TLS 1.3 or older.
   76|  4.29k|   m_extensions.deserialize(reader,
   77|  4.29k|                            Connection_Side::Server,
   78|  4.29k|                            m_is_hello_retry_request ? Handshake_Type::HelloRetryRequest : Handshake_Type::ServerHello);
  ------------------
  |  Branch (78:29): [True: 0, False: 4.29k]
  ------------------
   79|  4.29k|}
_ZNK5Botan3TLS21Server_Hello_Internal7versionEv:
   81|  8.46k|Protocol_Version Server_Hello_Internal::version() const {
   82|       |   // RFC 8446 4.2.1
   83|       |   //    A server which negotiates a version of TLS prior to TLS 1.3 MUST set
   84|       |   //    ServerHello.version and MUST NOT send the "supported_versions"
   85|       |   //    extension.  A server which negotiates TLS 1.3 MUST respond by sending
   86|       |   //    a "supported_versions" extension containing the selected version
   87|       |   //    value (0x0304).
   88|       |   //
   89|       |   // Note: Here we just take a message parsing decision, further validation of
   90|       |   //       the extension's contents is done later.
   91|  8.46k|   return (extensions().has<Supported_Versions>()) ? Protocol_Version::TLS_V13 : m_legacy_version;
  ------------------
  |  Branch (91:11): [True: 1.12k, False: 7.33k]
  ------------------
   92|  8.46k|}
_ZN5Botan3TLS12Server_HelloC2ENSt3__110unique_ptrINS0_21Server_Hello_InternalENS2_14default_deleteIS4_EEEE:
   94|  4.20k|Server_Hello::Server_Hello(std::unique_ptr<Server_Hello_Internal> data) : m_data(std::move(data)) {}
_ZN5Botan3TLS12Server_HelloC2EOS1_:
   96|  16.6k|Server_Hello::Server_Hello(Server_Hello&&) noexcept = default;
_ZN5Botan3TLS12Server_HelloD2Ev:
   99|  20.8k|Server_Hello::~Server_Hello() = default;
_ZNK5Botan3TLS12Server_Hello14legacy_versionEv:
  128|    590|Protocol_Version Server_Hello::legacy_version() const {
  129|    590|   return m_data->legacy_version();
  130|    590|}
_ZNK5Botan3TLS12Server_Hello18compression_methodEv:
  136|    546|uint8_t Server_Hello::compression_method() const {
  137|    546|   return m_data->comp_method();
  138|    546|}
_ZNK5Botan3TLS12Server_Hello10extensionsEv:
  152|  1.06k|const Extensions& Server_Hello::extensions() const {
  153|  1.06k|   return m_data->extensions();
  154|  1.06k|}
_ZN5Botan3TLS20Server_Hello_12_ShimC2ENSt3__110unique_ptrINS0_21Server_Hello_InternalENS2_14default_deleteIS4_EEEE:
  160|  3.63k|      Server_Hello(std::move(data)) {
  161|  3.63k|   if(!m_data->version().is_pre_tls_13()) {
  ------------------
  |  Branch (161:7): [True: 0, False: 3.63k]
  ------------------
  162|      0|      throw TLS_Exception(Alert::ProtocolVersion, "Expected server hello of (D)TLS 1.2 or lower");
  163|      0|   }
  164|  3.63k|}

_ZN5Botan3TLS23Renegotiation_ExtensionC2ERNS0_15TLS_Data_ReaderEt:
   24|    324|      m_reneg_data(reader.get_range<uint8_t>(1, 0, 255)) {
   25|    324|   if(m_reneg_data.size() + 1 != extension_size) {
  ------------------
  |  Branch (25:7): [True: 3, False: 321]
  ------------------
   26|      3|      throw Decoding_Error("Bad encoding for secure renegotiation extn");
   27|      3|   }
   28|    324|}
_ZN5Botan3TLS23Supported_Point_FormatsC2ERNS0_15TLS_Data_ReaderEt:
   45|    313|Supported_Point_Formats::Supported_Point_Formats(TLS_Data_Reader& reader, uint16_t extension_size) {
   46|    313|   const uint8_t len = reader.get_byte();
   47|       |
   48|    313|   if(len + 1 != extension_size) {
  ------------------
  |  Branch (48:7): [True: 10, False: 303]
  ------------------
   49|     10|      throw Decoding_Error("Inconsistent length field in supported point formats list");
   50|     10|   }
   51|       |
   52|    303|   bool includes_uncompressed = false;
   53|    805|   for(size_t i = 0; i != len; ++i) {
  ------------------
  |  Branch (53:22): [True: 784, False: 21]
  ------------------
   54|    784|      const uint8_t format = reader.get_byte();
   55|       |
   56|    784|      if(static_cast<ECPointFormat>(format) == UNCOMPRESSED) {
  ------------------
  |  Branch (56:10): [True: 70, False: 714]
  ------------------
   57|     70|         m_prefers_compressed = false;
   58|     70|         reader.discard_next(len - i - 1);
   59|     70|         return;
   60|    714|      } else if(static_cast<ECPointFormat>(format) == ANSIX962_COMPRESSED_PRIME) {
  ------------------
  |  Branch (60:17): [True: 212, False: 502]
  ------------------
   61|    212|         m_prefers_compressed = true;
   62|    212|         std::vector<uint8_t> remaining_formats = reader.get_fixed<uint8_t>(len - i - 1);
   63|    212|         includes_uncompressed =
   64|    212|            std::any_of(std::begin(remaining_formats), std::end(remaining_formats), [](uint8_t remaining_format) {
   65|    212|               return static_cast<ECPointFormat>(remaining_format) == UNCOMPRESSED;
   66|    212|            });
   67|    212|         break;
   68|    212|      }
   69|       |
   70|       |      // ignore ANSIX962_COMPRESSED_CHAR2, we don't support these curves
   71|    784|   }
   72|       |
   73|       |   // RFC 4492 5.1.:
   74|       |   //   If the Supported Point Formats Extension is indeed sent, it MUST contain the value 0 (uncompressed)
   75|       |   //   as one of the items in the list of point formats.
   76|       |   // Note:
   77|       |   //   RFC 8422 5.1.2. explicitly requires this check,
   78|       |   //   but only if the Supported Groups extension was sent.
   79|    233|   if(!includes_uncompressed) {
  ------------------
  |  Branch (79:7): [True: 28, False: 205]
  ------------------
   80|     28|      throw TLS_Exception(Alert::IllegalParameter,
   81|     28|                          "Supported Point Formats Extension must contain the uncompressed point format");
   82|     28|   }
   83|    233|}
_ZN5Botan3TLS24Session_Ticket_ExtensionC2ERNS0_15TLS_Data_ReaderEtNS0_15Connection_SideE:
   87|    452|                                                   Connection_Side from) {
   88|       |   // RFC 5077 3.2: in a ServerHello the SessionTicket extension is just a
   89|       |   // flag indicating that a NewSessionTicket handshake message will follow;
   90|       |   // its extension_data MUST be empty. A ticket body is only valid in a
   91|       |   // ClientHello.
   92|    452|   if(from == Connection_Side::Server && extension_size != 0) {
  ------------------
  |  Branch (92:7): [True: 203, False: 249]
  |  Branch (92:42): [True: 2, False: 201]
  ------------------
   93|      2|      throw Decoding_Error("Server sent a non-empty SessionTicket extension");
   94|      2|   }
   95|    450|   m_ticket = Session_Ticket(reader.get_elem<uint8_t, std::vector<uint8_t>>(extension_size));
   96|    450|}
_ZN5Botan3TLS22Extended_Master_SecretC2ERNS0_15TLS_Data_ReaderEt:
   98|     96|Extended_Master_Secret::Extended_Master_Secret(TLS_Data_Reader& /*unused*/, uint16_t extension_size) {
   99|     96|   if(extension_size != 0) {
  ------------------
  |  Branch (99:7): [True: 4, False: 92]
  ------------------
  100|      4|      throw Decoding_Error("Invalid extended_master_secret extension");
  101|      4|   }
  102|     96|}
_ZN5Botan3TLS16Encrypt_then_MACC2ERNS0_15TLS_Data_ReaderEt:
  108|    300|Encrypt_then_MAC::Encrypt_then_MAC(TLS_Data_Reader& /*unused*/, uint16_t extension_size) {
  109|    300|   if(extension_size != 0) {
  ------------------
  |  Branch (109:7): [True: 10, False: 290]
  ------------------
  110|     10|      throw Decoding_Error("Invalid encrypt_then_mac extension");
  111|     10|   }
  112|    300|}
tls_extensions_12.cpp:_ZZN5Botan3TLS23Supported_Point_FormatsC1ERNS0_15TLS_Data_ReaderEtENK3$_0clEh:
   64|    617|            std::any_of(std::begin(remaining_formats), std::end(remaining_formats), [](uint8_t remaining_format) {
   65|    617|               return static_cast<ECPointFormat>(remaining_format) == UNCOMPRESSED;
   66|    617|            });

_ZN5Botan3TLS21Certificate_Verify_13C2ENSt3__14spanIKhLm18446744073709551615EEENS0_15Connection_SideE:
   87|  2.50k|      Certificate_Verify(buf), m_side(side) {
   88|  2.50k|   if(!m_scheme.is_available()) {
  ------------------
  |  Branch (88:7): [True: 93, False: 2.40k]
  ------------------
   89|     93|      throw TLS_Exception(Alert::IllegalParameter, "Peer sent unknown signature scheme");
   90|     93|   }
   91|       |
   92|  2.40k|   if(!m_scheme.is_compatible_with(Protocol_Version::TLS_V13)) {
  ------------------
  |  Branch (92:7): [True: 5, False: 2.40k]
  ------------------
   93|      5|      throw TLS_Exception(Alert::IllegalParameter, "Peer sent signature algorithm that is not suitable for TLS 1.3");
   94|      5|   }
   95|  2.40k|}

_ZN5Botan3TLS14Certificate_1317Certificate_EntryC2ERNS0_15TLS_Data_ReaderENS0_15Connection_SideENS0_16Certificate_TypeE:
  278|  2.93k|                                                     Certificate_Type cert_type) {
  279|  2.93k|   if(cert_type == Certificate_Type::X509) {
  ------------------
  |  Branch (279:7): [True: 2.93k, False: 0]
  ------------------
  280|       |      // RFC 8446 4.2.2
  281|       |      //    [...] each CertificateEntry contains a DER-encoded X.509
  282|       |      //    certificate.
  283|  2.93k|      const auto cert_bytes = reader.get_tls_length_value(3);
  284|  2.93k|      try {
  285|  2.93k|         m_certificate = std::make_unique<X509_Certificate>(cert_bytes);
  286|  2.93k|         m_raw_public_key = m_certificate->subject_public_key();
  287|  2.93k|      } catch(Exception& e) {
  288|       |         // bad_certificate would make more sense but BoGo expects decoding_error
  289|  2.92k|         throw TLS_Exception(Alert::DecodeError, e.what());
  290|  2.92k|      }
  291|  2.93k|   } else if(cert_type == Certificate_Type::RawPublicKey) {
  ------------------
  |  Branch (291:14): [True: 0, False: 0]
  ------------------
  292|       |      // RFC 7250 3.
  293|       |      //    This specification uses raw public keys whereby the already
  294|       |      //    available encoding used in a PKIX certificate in the form of a
  295|       |      //    SubjectPublicKeyInfo structure is reused.
  296|      0|      try {
  297|      0|         m_raw_public_key = X509::load_key(reader.get_tls_length_value(3));
  298|      0|      } catch(Exception& e) {
  299|      0|         throw TLS_Exception(Alert::DecodeError, e.what());
  300|      0|      }
  301|      0|   } else {
  302|      0|      throw TLS_Exception(Alert::InternalError, "Unknown certificate type");
  303|      0|   }
  304|       |
  305|       |   // Extensions are simply tacked at the end of the certificate entry. This
  306|       |   // is a departure from the typical "tag-length-value" in a sense that the
  307|       |   // Extensions deserializer needs the length value of the extensions.
  308|      0|   const size_t extensions_length = reader.peek_uint16_t();
  309|      0|   const auto exts_buf = reader.get_fixed<uint8_t>(extensions_length + 2);
  310|      0|   TLS_Data_Reader exts_reader("extensions reader", exts_buf);
  311|      0|   m_extensions.deserialize(exts_reader, side, Handshake_Type::Certificate);
  312|       |
  313|      0|   if(cert_type == Certificate_Type::X509) {
  ------------------
  |  Branch (313:7): [True: 0, False: 0]
  ------------------
  314|       |      // RFC 8446 4.4.2
  315|       |      //    Valid extensions for server certificates at present include the
  316|       |      //    OCSP Status extension [RFC6066] and the SignedCertificateTimestamp
  317|       |      //    extension [RFC6962]; future extensions may be defined for this
  318|       |      //    message as well.
  319|       |      //
  320|       |      // RFC 8446 4.4.2.1
  321|       |      //    A server MAY request that a client present an OCSP response with its
  322|       |      //    certificate by sending an empty "status_request" extension in its
  323|       |      //    CertificateRequest message.
  324|      0|      if(m_extensions.contains_implemented_extensions_other_than({
  ------------------
  |  Branch (324:10): [True: 0, False: 0]
  ------------------
  325|      0|            Extension_Code::CertificateStatusRequest,
  326|       |            // Extension_Code::SignedCertificateTimestamp
  327|      0|         })) {
  328|      0|         throw TLS_Exception(Alert::IllegalParameter, "Certificate Entry contained an extension that is not allowed");
  329|      0|      }
  330|      0|   } else if(m_extensions.contains_implemented_extensions_other_than({})) {
  ------------------
  |  Branch (330:14): [True: 0, False: 0]
  ------------------
  331|      0|      throw TLS_Exception(
  332|      0|         Alert::IllegalParameter,
  333|      0|         "Certificate Entry holding something else than a certificate contained unexpected extensions");
  334|      0|   }
  335|      0|}
_ZN5Botan3TLS14Certificate_13C2ENSt3__14spanIKhLm18446744073709551615EEERKNS0_6PolicyENS0_15Connection_SideENS0_16Certificate_TypeE:
  372|  2.97k|      m_side(side) {
  373|  2.97k|   TLS_Data_Reader reader("cert message reader", buf);
  374|       |
  375|  2.97k|   m_request_context = reader.get_range<uint8_t>(1, 0, 255);
  376|       |
  377|       |   // RFC 8446 4.4.2
  378|       |   //    [...] in the case of server authentication, this field SHALL be zero length.
  379|  2.97k|   if(m_side == Connection_Side::Server && !m_request_context.empty()) {
  ------------------
  |  Branch (379:7): [True: 2.97k, False: 4]
  |  Branch (379:44): [True: 12, False: 2.96k]
  ------------------
  380|     12|      throw TLS_Exception(Alert::IllegalParameter, "Server Certificate message must not contain a request context");
  381|     12|   }
  382|       |
  383|  2.96k|   const auto cert_entries_len = reader.get_uint24_t();
  384|       |
  385|  2.96k|   if(reader.remaining_bytes() != cert_entries_len) {
  ------------------
  |  Branch (385:7): [True: 27, False: 2.94k]
  ------------------
  386|     27|      throw TLS_Exception(Alert::DecodeError, "Certificate: Message malformed");
  387|     27|   }
  388|       |
  389|  2.94k|   const size_t max_size = policy.maximum_certificate_chain_size();
  390|  2.94k|   if(max_size > 0 && cert_entries_len > max_size) {
  ------------------
  |  Branch (390:7): [True: 2.93k, False: 5]
  |  Branch (390:23): [True: 0, False: 2.93k]
  ------------------
  391|      0|      throw Decoding_Error("Certificate chain exceeds policy specified maximum size");
  392|      0|   }
  393|       |
  394|  5.87k|   while(reader.has_remaining()) {
  ------------------
  |  Branch (394:10): [True: 2.93k, False: 2.94k]
  ------------------
  395|  2.93k|      m_entries.emplace_back(reader, side, cert_type);
  396|  2.93k|   }
  397|       |
  398|       |   // RFC 8446 4.4.2
  399|       |   //    The server's certificate_list MUST always be non-empty.  A client
  400|       |   //    will send an empty certificate_list if it does not have an
  401|       |   //    appropriate certificate to send in response to the server's
  402|       |   //    authentication request.
  403|  2.94k|   if(m_entries.empty()) {
  ------------------
  |  Branch (403:7): [True: 1, False: 2.93k]
  ------------------
  404|       |      // RFC 8446 4.4.2.4
  405|       |      //    If the server supplies an empty Certificate message, the client MUST
  406|       |      //    abort the handshake with a "decode_error" alert.
  407|      1|      if(m_side == Connection_Side::Server) {
  ------------------
  |  Branch (407:10): [True: 1, False: 0]
  ------------------
  408|      1|         throw TLS_Exception(Alert::DecodeError, "No certificates sent by server");
  409|      1|      }
  410|       |
  411|      0|      return;
  412|      1|   }
  413|       |
  414|  2.93k|   BOTAN_ASSERT_NOMSG(!m_entries.empty());
  ------------------
  |  |   84|  2.93k|   do {                                                                     \
  |  |   85|  2.93k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  2.93k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 2.93k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  2.93k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 2.93k]
  |  |  ------------------
  ------------------
  415|       |
  416|       |   // RFC 8446 4.4.2.2
  417|       |   //    The certificate type MUST be X.509v3 [RFC5280], unless explicitly
  418|       |   //    negotiated otherwise (e.g., [RFC7250]).
  419|       |   //
  420|       |   // TLS 1.0 through 1.3 all seem to require that the certificate be
  421|       |   // precisely a v3 certificate. In fact the strict wording would seem
  422|       |   // to require that every certificate in the chain be v3. But often
  423|       |   // the intermediates are outside of the control of the server.
  424|       |   // But, require that the leaf certificate be v3.
  425|  2.93k|   if(cert_type == Certificate_Type::X509 && m_entries.front().certificate().x509_version() != 3) {
  ------------------
  |  Branch (425:7): [True: 0, False: 2.93k]
  |  Branch (425:46): [True: 0, False: 0]
  ------------------
  426|      0|      throw TLS_Exception(Alert::BadCertificate, "The leaf certificate must be v3");
  427|      0|   }
  428|       |
  429|       |   // RFC 8446 4.4.2
  430|       |   //    If the RawPublicKey certificate type was negotiated, then the
  431|       |   //    certificate_list MUST contain no more than one CertificateEntry.
  432|  2.93k|   if(cert_type == Certificate_Type::RawPublicKey && m_entries.size() != 1) {
  ------------------
  |  Branch (432:7): [True: 0, False: 2.93k]
  |  Branch (432:54): [True: 0, False: 0]
  ------------------
  433|      0|      throw TLS_Exception(Alert::IllegalParameter, "Certificate message contained more than one RawPublicKey");
  434|      0|   }
  435|       |
  436|       |   // Validate the provided (certificate) public key against our policy
  437|  2.93k|   auto pubkey = public_key();
  438|  2.93k|   policy.check_peer_key_acceptable(*pubkey);
  439|       |
  440|  2.93k|   if(!policy.allowed_signature_method(pubkey->algo_name())) {
  ------------------
  |  Branch (440:7): [True: 0, False: 2.93k]
  ------------------
  441|      0|      throw TLS_Exception(Alert::HandshakeFailure, "Rejecting " + pubkey->algo_name() + " signature");
  442|      0|   }
  443|  2.93k|}

_ZNK5Botan3TLS22Certificate_Request_134typeEv:
   21|  1.67k|Handshake_Type Certificate_Request_13::type() const {
   22|  1.67k|   return TLS::Handshake_Type::CertificateRequest;
   23|  1.67k|}
_ZN5Botan3TLS22Certificate_Request_13C2ENSt3__14spanIKhLm18446744073709551615EEENS0_15Connection_SideE:
   25|  1.68k|Certificate_Request_13::Certificate_Request_13(std::span<const uint8_t> buf, const Connection_Side side) {
   26|  1.68k|   TLS_Data_Reader reader("Certificate_Request_13", buf);
   27|       |
   28|       |   // RFC 8446 4.3.2
   29|       |   //    A server which is authenticating with a certificate MAY optionally
   30|       |   //    request a certificate from the client.
   31|  1.68k|   if(side != Connection_Side::Server) {
  ------------------
  |  Branch (31:7): [True: 0, False: 1.68k]
  ------------------
   32|      0|      throw TLS_Exception(Alert::UnexpectedMessage, "Received a Certificate_Request message from a client");
   33|      0|   }
   34|       |
   35|  1.68k|   m_context = reader.get_tls_length_value(1);
   36|  1.68k|   m_extensions.deserialize(reader, side, type());
   37|       |
   38|       |   // RFC 8446 4.3.2
   39|       |   //    The "signature_algorithms" extension MUST be specified, and other
   40|       |   //    extensions may optionally be included if defined for this message.
   41|       |   //    Clients MUST ignore unrecognized extensions.
   42|       |
   43|  1.68k|   if(!m_extensions.has<Signature_Algorithms>()) {
  ------------------
  |  Branch (43:7): [True: 71, False: 1.61k]
  ------------------
   44|     71|      throw TLS_Exception(Alert::MissingExtension,
   45|     71|                          "Certificate_Request message did not provide a signature_algorithms extension");
   46|     71|   }
   47|       |
   48|       |   // RFC 8446 4.2.
   49|       |   //    The table below indicates the messages where a given extension may
   50|       |   //    appear [...].  If an implementation receives an extension which it
   51|       |   //    recognizes and which is not specified for the message in which it
   52|       |   //    appears, it MUST abort the handshake with an "illegal_parameter" alert.
   53|       |   //
   54|       |   // For Certificate Request said table states:
   55|       |   //    "status_request", "signature_algorithms", "signed_certificate_timestamp",
   56|       |   //     "certificate_authorities", "oid_filters", "signature_algorithms_cert",
   57|  1.61k|   const std::set<Extension_Code> allowed_extensions = {
   58|  1.61k|      Extension_Code::CertificateStatusRequest,
   59|  1.61k|      Extension_Code::SignatureAlgorithms,
   60|       |      // Extension_Code::SignedCertificateTimestamp,  // NYI
   61|  1.61k|      Extension_Code::CertificateAuthorities,
   62|       |      // Extension_Code::OidFilters,                   // NYI
   63|  1.61k|      Extension_Code::CertSignatureAlgorithms,
   64|  1.61k|   };
   65|       |
   66|  1.61k|   if(m_extensions.contains_implemented_extensions_other_than(allowed_extensions)) {
  ------------------
  |  Branch (66:7): [True: 4, False: 1.60k]
  ------------------
   67|      4|      throw TLS_Exception(Alert::IllegalParameter, "Certificate Request contained an extension that is not allowed");
   68|      4|   }
   69|       |
   70|  1.60k|   reader.assert_done();
   71|  1.60k|}

_ZN5Botan3TLS15Client_Hello_13C2ENSt3__110unique_ptrINS0_21Client_Hello_InternalENS2_14default_deleteIS4_EEEE:
   30|    366|Client_Hello_13::Client_Hello_13(std::unique_ptr<Client_Hello_Internal> data) : Client_Hello(std::move(data)) {
   31|    366|   const auto& exts = m_data->extensions();
   32|       |
   33|       |   // RFC 8446 4.1.2
   34|       |   //    TLS 1.3 ClientHellos are identified as having a legacy_version of
   35|       |   //    0x0303 and a "supported_versions" extension present with 0x0304 as the
   36|       |   //    highest version indicated therein.
   37|       |   //
   38|       |   // Note that we already checked for "supported_versions" before entering this
   39|       |   // c'tor in `Client_Hello_13::parse()`. This is just to be doubly sure.
   40|    366|   BOTAN_ASSERT_NOMSG(exts.has<Supported_Versions>());
  ------------------
  |  |   84|    366|   do {                                                                     \
  |  |   85|    366|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|    366|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 366]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|    366|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 366]
  |  |  ------------------
  ------------------
   41|       |
   42|       |   // RFC 8446 4.2.1
   43|       |   //    Servers MAY abort the handshake upon receiving a ClientHello with
   44|       |   //    legacy_version 0x0304 or later.
   45|    366|   if(m_data->legacy_version().is_tls_13_or_later()) {
  ------------------
  |  Branch (45:7): [True: 27, False: 339]
  ------------------
   46|     27|      throw TLS_Exception(Alert::DecodeError, "TLS 1.3 Client Hello has invalid legacy_version");
   47|     27|   }
   48|       |
   49|       |   // RFC 8446 D.5
   50|       |   //    Any endpoint receiving a Hello message with ClientHello.legacy_version [...]
   51|       |   //    set to 0x0300 MUST abort the handshake with a "protocol_version" alert.
   52|    339|   if(m_data->legacy_version().major_version() == 3 && m_data->legacy_version().minor_version() == 0) {
  ------------------
  |  Branch (52:7): [True: 125, False: 214]
  |  Branch (52:7): [True: 1, False: 338]
  |  Branch (52:56): [True: 1, False: 124]
  ------------------
   53|      1|      throw TLS_Exception(Alert::ProtocolVersion, "TLS 1.3 Client Hello has invalid legacy_version");
   54|      1|   }
   55|       |
   56|       |   // RFC 8446 4.1.2
   57|       |   //    For every TLS 1.3 ClientHello, [the compression method] MUST contain
   58|       |   //    exactly one byte, set to zero, [...].  If a TLS 1.3 ClientHello is
   59|       |   //    received with any other value in this field, the server MUST abort the
   60|       |   //    handshake with an "illegal_parameter" alert.
   61|    338|   if(m_data->comp_methods().size() != 1 || m_data->comp_methods().front() != 0) {
  ------------------
  |  Branch (61:7): [True: 1, False: 337]
  |  Branch (61:45): [True: 15, False: 322]
  ------------------
   62|     16|      throw TLS_Exception(Alert::IllegalParameter, "Client did not offer NULL compression");
   63|     16|   }
   64|       |
   65|       |   // RFC 8446 4.2.9
   66|       |   //    A client MUST provide a "psk_key_exchange_modes" extension if it
   67|       |   //    offers a "pre_shared_key" extension. If clients offer "pre_shared_key"
   68|       |   //    without a "psk_key_exchange_modes" extension, servers MUST abort
   69|       |   //    the handshake.
   70|    322|   if(exts.has<PSK>()) {
  ------------------
  |  Branch (70:7): [True: 85, False: 237]
  ------------------
   71|     85|      if(!exts.has<PSK_Key_Exchange_Modes>()) {
  ------------------
  |  Branch (71:10): [True: 1, False: 84]
  ------------------
   72|      1|         throw TLS_Exception(Alert::MissingExtension,
   73|      1|                             "Client Hello offered a PSK without a psk_key_exchange_modes extension");
   74|      1|      }
   75|       |
   76|       |      // RFC 8446 4.2.11
   77|       |      //     The "pre_shared_key" extension MUST be the last extension in the
   78|       |      //     ClientHello [...]. Servers MUST check that it is the last extension
   79|       |      //     and otherwise fail the handshake with an "illegal_parameter" alert.
   80|     84|      if(exts.last_added() != Extension_Code::PresharedKey) {
  ------------------
  |  Branch (80:10): [True: 4, False: 80]
  ------------------
   81|      4|         throw TLS_Exception(Alert::IllegalParameter, "PSK extension was not at the very end of the Client Hello");
   82|      4|      }
   83|     84|   }
   84|       |
   85|       |   // RFC 8446 9.2
   86|       |   //    [A TLS 1.3 ClientHello] message MUST meet the following requirements:
   87|       |   //
   88|       |   //     -  If not containing a "pre_shared_key" extension, it MUST contain
   89|       |   //        both a "signature_algorithms" extension and a "supported_groups"
   90|       |   //        extension.
   91|       |   //
   92|       |   //     -  If containing a "supported_groups" extension, it MUST also contain
   93|       |   //        a "key_share" extension, and vice versa.  An empty
   94|       |   //        KeyShare.client_shares vector is permitted.
   95|       |   //
   96|       |   //    Servers receiving a ClientHello which does not conform to these
   97|       |   //    requirements MUST abort the handshake with a "missing_extension"
   98|       |   //    alert.
   99|    317|   if(!exts.has<PSK>()) {
  ------------------
  |  Branch (99:7): [True: 237, False: 80]
  ------------------
  100|    237|      if(!exts.has<Supported_Groups>() || !exts.has<Signature_Algorithms>()) {
  ------------------
  |  Branch (100:10): [True: 2, False: 235]
  |  Branch (100:43): [True: 1, False: 234]
  ------------------
  101|      3|         throw TLS_Exception(
  102|      3|            Alert::MissingExtension,
  103|      3|            "Non-PSK Client Hello did not contain supported_groups and signature_algorithms extensions");
  104|      3|      }
  105|    237|   }
  106|    314|   if(exts.has<Supported_Groups>() != exts.has<Key_Share>()) {
  ------------------
  |  Branch (106:7): [True: 1, False: 313]
  ------------------
  107|      1|      throw TLS_Exception(Alert::MissingExtension,
  108|      1|                          "Client Hello must either contain both key_share and supported_groups extensions or neither");
  109|      1|   }
  110|       |
  111|    313|   if(exts.has<Key_Share>()) {
  ------------------
  |  Branch (111:7): [True: 233, False: 80]
  ------------------
  112|    233|      auto* const supported_ext = exts.get<Supported_Groups>();
  113|    233|      BOTAN_ASSERT_NONNULL(supported_ext);
  ------------------
  |  |  123|    233|   do {                                                                                   \
  |  |  124|    233|      if((ptr) == nullptr) {                                                              \
  |  |  ------------------
  |  |  |  Branch (124:10): [True: 0, False: 233]
  |  |  ------------------
  |  |  125|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                              \
  |  |  126|      0|         Botan::assertion_failure(#ptr " is not null", "", __func__, __FILE__, __LINE__); \
  |  |  127|      0|      }                                                                                   \
  |  |  128|    233|   } while(0)
  |  |  ------------------
  |  |  |  Branch (128:12): [Folded, False: 233]
  |  |  ------------------
  ------------------
  114|    233|      const auto supports = supported_ext->groups();
  115|    233|      const auto offers = exts.get<Key_Share>()->offered_groups();
  116|       |
  117|       |      // RFC 8446 4.2.8
  118|       |      //    Each KeyShareEntry value MUST correspond to a group offered in the
  119|       |      //    "supported_groups" extension and MUST appear in the same order.
  120|       |      //    [...]
  121|       |      //    Clients MUST NOT offer any KeyShareEntry values for groups not
  122|       |      //    listed in the client's "supported_groups" extension.
  123|       |      //
  124|       |      //    Servers MAY check for violations of these rules and abort the
  125|       |      //    handshake with an "illegal_parameter" alert if one is violated.
  126|       |      //
  127|       |      // Note: We can assume that both `offers` and `supports` are unique lists
  128|       |      //       as this is ensured in the parsing code of the extensions.
  129|       |      //
  130|       |      // Since offers must appear in the same order as supports, a single
  131|       |      // forward sweep of `supports` suffices: after finding each offered group
  132|       |      // we advance past its position so the next offered group is searched for
  133|       |      // only in the remaining suffix.
  134|    233|      auto supports_it = supports.begin();
  135|    284|      for(const auto offered : offers) {
  ------------------
  |  Branch (135:30): [True: 284, False: 211]
  ------------------
  136|    284|         supports_it = std::find(supports_it, supports.end(), offered);
  137|    284|         if(supports_it == supports.end()) {
  ------------------
  |  Branch (137:13): [True: 22, False: 262]
  ------------------
  138|     22|            throw TLS_Exception(Alert::IllegalParameter,
  139|     22|                                "Offered key exchange groups do not align with claimed supported groups");
  140|     22|         }
  141|    262|         ++supports_it;
  142|    262|      }
  143|    233|   }
  144|       |
  145|       |   // TODO: Reject oid_filters extension if found (which is the only known extension that
  146|       |   //       must not occur in the TLS 1.3 client hello.
  147|       |   // RFC 8446 4.2.5
  148|       |   //    [The oid_filters extension] MUST only be sent in the CertificateRequest message.
  149|    313|}
_ZN5Botan3TLS15Client_Hello_135parseENSt3__14spanIKhLm18446744073709551615EEE:
  286|  6.01k|std::variant<Client_Hello_13, Client_Hello_12_Shim> Client_Hello_13::parse(std::span<const uint8_t> buf) {
  287|  6.01k|   auto data = std::make_unique<Client_Hello_Internal>(buf);
  288|  6.01k|   const auto version = data->version();
  289|       |
  290|  6.01k|   if(version.is_pre_tls_13()) {
  ------------------
  |  Branch (290:7): [True: 5.18k, False: 833]
  ------------------
  291|  5.18k|      return Client_Hello_12_Shim(std::move(data));
  292|  5.18k|   } else {
  293|    833|      return Client_Hello_13(std::move(data));
  294|    833|   }
  295|  6.01k|}

_ZN5Botan3TLS20Encrypted_ExtensionsC2ENSt3__14spanIKhLm18446744073709551615EEE:
  134|  7.16k|Encrypted_Extensions::Encrypted_Extensions(std::span<const uint8_t> buf) {
  135|  7.16k|   TLS_Data_Reader reader("encrypted extensions reader", buf);
  136|       |
  137|       |   // Encrypted Extensions contains a list of extensions. This list may legally
  138|       |   // be empty. However, in that case we should at least see a two-byte length
  139|       |   // field that reads 0x00 0x00.
  140|  7.16k|   if(buf.size() < 2) {
  ------------------
  |  Branch (140:7): [True: 11, False: 7.14k]
  ------------------
  141|     11|      throw TLS_Exception(Alert::DecodeError, "Server sent an empty Encrypted Extensions message");
  142|     11|   }
  143|       |
  144|  7.14k|   m_extensions.deserialize(reader, Connection_Side::Server, type());
  145|       |
  146|       |   // RFC 8446 4.2
  147|       |   //    If an implementation receives an extension which it recognizes and
  148|       |   //    which is not specified for the message in which it appears, it MUST
  149|       |   //    abort the handshake with an "illegal_parameter" alert.
  150|       |   //
  151|       |   // Note that we cannot encounter any extensions that we don't recognize here,
  152|       |   // since only extensions we previously offered are allowed in EE.
  153|  7.14k|   const auto allowed_exts = std::set<Extension_Code>{
  154|       |      // Allowed extensions listed in RFC 8446 and implemented in Botan
  155|  7.14k|      Extension_Code::ServerNameIndication,
  156|       |      // MAX_FRAGMENT_LENGTH
  157|  7.14k|      Extension_Code::SupportedGroups,
  158|  7.14k|      Extension_Code::UseSrtp,
  159|       |      // HEARTBEAT
  160|  7.14k|      Extension_Code::ApplicationLayerProtocolNegotiation,
  161|       |      // RFC 7250
  162|  7.14k|      Extension_Code::ClientCertificateType,
  163|  7.14k|      Extension_Code::ServerCertificateType,
  164|       |      // EARLY_DATA
  165|       |
  166|       |      // Allowed extensions not listed in RFC 8446 but acceptable as Botan implements them
  167|  7.14k|      Extension_Code::RecordSizeLimit,
  168|  7.14k|   };
  169|  7.14k|   if(m_extensions.contains_implemented_extensions_other_than(allowed_exts)) {
  ------------------
  |  Branch (169:7): [True: 107, False: 7.04k]
  ------------------
  170|    107|      throw TLS_Exception(Alert::IllegalParameter, "Encrypted Extensions contained an extension that is not allowed");
  171|    107|   }
  172|       |
  173|  7.04k|   reader.assert_done();
  174|  7.04k|}

_ZN5Botan3TLS15Server_Hello_135parseENSt3__14spanIKhLm18446744073709551615EEE:
   85|  4.31k|   std::span<const uint8_t> buf) {
   86|  4.31k|   auto data = std::make_unique<Server_Hello_Internal>(buf);
   87|  4.31k|   const auto version = data->version();
   88|       |
   89|       |   // server hello that appears to be pre-TLS 1.3, takes precedence over...
   90|  4.31k|   if(version.is_pre_tls_13()) {
  ------------------
  |  Branch (90:7): [True: 3.63k, False: 680]
  ------------------
   91|  3.63k|      return Server_Hello_12_Shim(std::move(data));
   92|  3.63k|   }
   93|       |
   94|       |   // ... the TLS 1.3 "special case" aka. Hello_Retry_Request
   95|    680|   if(version == Protocol_Version::TLS_V13) {
  ------------------
  |  Branch (95:7): [True: 568, False: 112]
  ------------------
   96|    568|      if(data->is_hello_retry_request()) {
  ------------------
  |  Branch (96:10): [True: 0, False: 568]
  ------------------
   97|      0|         return Hello_Retry_Request(std::move(data));
   98|      0|      }
   99|       |
  100|    568|      return Server_Hello_13(std::move(data));
  101|    568|   }
  102|       |
  103|    112|   throw TLS_Exception(Alert::ProtocolVersion, "unexpected server hello version: " + version.to_string());
  104|    680|}
_ZNK5Botan3TLS15Server_Hello_1316basic_validationEv:
  109|    568|void Server_Hello_13::basic_validation() const {
  110|    568|   BOTAN_ASSERT_NOMSG(m_data->version() == Protocol_Version::TLS_V13);
  ------------------
  |  |   84|    568|   do {                                                                     \
  |  |   85|    568|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|    568|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 568]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|    568|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 568]
  |  |  ------------------
  ------------------
  111|       |
  112|       |   // Note: checks that cannot be performed without contextual information
  113|       |   //       are done in the specific TLS client implementation.
  114|       |   // Note: The Supported_Version extension makes sure internally that
  115|       |   //       exactly one entry is provided.
  116|       |
  117|       |   // Note: Hello Retry Request basic validation is equivalent with the
  118|       |   //       basic validations required for Server Hello
  119|       |   //
  120|       |   // RFC 8446 4.1.4
  121|       |   //    Upon receipt of a HelloRetryRequest, the client MUST check the
  122|       |   //    legacy_version, [...], and legacy_compression_method as specified in
  123|       |   //    Section 4.1.3 and then process the extensions, starting with determining
  124|       |   //    the version using "supported_versions".
  125|       |
  126|       |   // RFC 8446 4.1.3
  127|       |   //    In TLS 1.3, [...] the legacy_version field MUST be set to 0x0303
  128|    568|   if(legacy_version() != Protocol_Version::TLS_V12) {
  ------------------
  |  Branch (128:7): [True: 22, False: 546]
  ------------------
  129|     22|      throw TLS_Exception(Alert::ProtocolVersion,
  130|     22|                          "legacy_version '" + legacy_version().to_string() + "' is not allowed");
  131|     22|   }
  132|       |
  133|       |   // RFC 8446 4.1.3
  134|       |   //    legacy_compression_method:  A single byte which MUST have the value 0.
  135|    546|   if(compression_method() != 0x00) {
  ------------------
  |  Branch (135:7): [True: 6, False: 540]
  ------------------
  136|      6|      throw TLS_Exception(Alert::DecodeError, "compression is not supported in TLS 1.3");
  137|      6|   }
  138|       |
  139|       |   // RFC 8446 4.1.3
  140|       |   //    All TLS 1.3 ServerHello messages MUST contain the "supported_versions" extension.
  141|    540|   if(!extensions().has<Supported_Versions>()) {
  ------------------
  |  Branch (141:7): [True: 0, False: 540]
  ------------------
  142|      0|      throw TLS_Exception(Alert::MissingExtension, "server hello did not contain 'supported version' extension");
  143|      0|   }
  144|       |
  145|       |   // RFC 8446 4.2.1
  146|       |   //    A server which negotiates TLS 1.3 MUST respond by sending
  147|       |   //    a "supported_versions" extension containing the selected version
  148|       |   //    value (0x0304).
  149|    540|   if(selected_version() != Protocol_Version::TLS_V13) {
  ------------------
  |  Branch (149:7): [True: 12, False: 528]
  ------------------
  150|     12|      throw TLS_Exception(Alert::IllegalParameter, "TLS 1.3 Server Hello selected a different version");
  151|     12|   }
  152|    540|}
_ZN5Botan3TLS15Server_Hello_13C2ENSt3__110unique_ptrINS0_21Server_Hello_InternalENS2_14default_deleteIS4_EEEENS1_16Server_Hello_TagE:
  156|    568|      Server_Hello(std::move(data)) {
  157|    568|   BOTAN_ASSERT_NOMSG(!m_data->is_hello_retry_request());
  ------------------
  |  |   84|    568|   do {                                                                     \
  |  |   85|    568|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|    568|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 568]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|    568|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 568]
  |  |  ------------------
  ------------------
  158|    568|   basic_validation();
  159|       |
  160|    568|   const auto& exts = extensions();
  161|       |
  162|       |   // RFC 8446 4.1.3
  163|       |   //    The ServerHello MUST only include extensions which are required to
  164|       |   //    establish the cryptographic context and negotiate the protocol version.
  165|       |   //    [...]
  166|       |   //    Other extensions (see Section 4.2) are sent separately in the
  167|       |   //    EncryptedExtensions message.
  168|       |   //
  169|       |   // Note that further validation dependent on the client hello is done in the
  170|       |   // TLS client implementation.
  171|    568|   const std::set<Extension_Code> allowed = {
  172|    568|      Extension_Code::KeyShare,
  173|    568|      Extension_Code::SupportedVersions,
  174|    568|      Extension_Code::PresharedKey,
  175|    568|   };
  176|       |
  177|       |   // As the ServerHello shall only contain essential extensions, we don't give
  178|       |   // any slack for extensions not implemented by Botan here.
  179|    568|   if(exts.contains_other_than(allowed)) {
  ------------------
  |  Branch (179:7): [True: 3, False: 565]
  ------------------
  180|      3|      throw TLS_Exception(Alert::UnsupportedExtension, "Server Hello contained an extension that is not allowed");
  181|      3|   }
  182|       |
  183|       |   // RFC 8446 4.1.3
  184|       |   //    Current ServerHello messages additionally contain
  185|       |   //    either the "pre_shared_key" extension or the "key_share"
  186|       |   //    extension, or both [...].
  187|    565|   if(!exts.has<Key_Share>() && !exts.has<PSK>()) {
  ------------------
  |  Branch (187:7): [True: 373, False: 192]
  |  Branch (187:33): [True: 1, False: 372]
  ------------------
  188|      1|      throw TLS_Exception(Alert::MissingExtension, "server hello must contain key exchange information");
  189|      1|   }
  190|    565|}
_ZNK5Botan3TLS15Server_Hello_1316selected_versionEv:
  353|    540|Protocol_Version Server_Hello_13::selected_version() const {
  354|    540|   auto* const versions_ext = m_data->extensions().get<Supported_Versions>();
  355|    540|   BOTAN_ASSERT_NOMSG(versions_ext);
  ------------------
  |  |   84|    540|   do {                                                                     \
  |  |   85|    540|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|    540|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 540]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|    540|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 540]
  |  |  ------------------
  ------------------
  356|    540|   const auto& versions = versions_ext->versions();
  357|    540|   BOTAN_ASSERT_NOMSG(versions.size() == 1);
  ------------------
  |  |   84|    540|   do {                                                                     \
  |  |   85|    540|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|    540|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 540]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|    540|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 540]
  |  |  ------------------
  ------------------
  358|    540|   return versions.front();
  359|    540|}

_ZN5Botan3TLS6CookieC2ERNS0_15TLS_Data_ReaderEt:
   26|    232|Cookie::Cookie(TLS_Data_Reader& reader, uint16_t extension_size) {
   27|       |   // RFC 8446 4.2.2
   28|       |   //    struct {
   29|       |   //       opaque cookie<1..2^16-1>;
   30|       |   //    } Cookie;
   31|       |   //
   32|       |   // The wire form requires a 2-byte length field plus at least one byte of
   33|       |   // cookie data, so the minimum extension size is 3 bytes.
   34|    232|   if(extension_size < 3) {
  ------------------
  |  Branch (34:7): [True: 2, False: 230]
  ------------------
   35|      2|      throw Decoding_Error("Empty cookie extension is illegal");
   36|      2|   }
   37|       |
   38|    230|   const uint16_t len = reader.get_uint16_t();
   39|       |
   40|    230|   if(static_cast<size_t>(len) + 2 != extension_size) {
  ------------------
  |  Branch (40:7): [True: 22, False: 208]
  ------------------
   41|     22|      throw Decoding_Error("Inconsistent length in cookie extension");
   42|     22|   }
   43|       |
   44|    208|   m_cookie = reader.get_fixed<uint8_t>(len);
   45|    208|}
_ZN5Botan3TLS22PSK_Key_Exchange_ModesC2ERNS0_15TLS_Data_ReaderEt:
   65|    700|PSK_Key_Exchange_Modes::PSK_Key_Exchange_Modes(TLS_Data_Reader& reader, uint16_t extension_size) {
   66|       |   // RFC 8446 4.2.9
   67|       |   //    struct {
   68|       |   //       PskKeyExchangeMode ke_modes<1..255>;
   69|       |   //    } PskKeyExchangeModes;
   70|       |   //
   71|       |   // The wire form is a 1-byte length followed by mode_count mode bytes,
   72|       |   // with mode_count in [1, 255], so the extension size is in [2, 256].
   73|    700|   if(extension_size < 2) {
  ------------------
  |  Branch (73:7): [True: 2, False: 698]
  ------------------
   74|      2|      throw Decoding_Error("Empty psk_key_exchange_modes extension is illegal");
   75|      2|   }
   76|       |
   77|    698|   const auto mode_count = reader.get_byte();
   78|    698|   if(static_cast<size_t>(mode_count) + 1 != extension_size) {
  ------------------
  |  Branch (78:7): [True: 11, False: 687]
  ------------------
   79|     11|      throw Decoding_Error("Inconsistent length in psk_key_exchange_modes extension");
   80|     11|   }
   81|       |
   82|  3.87k|   for(uint16_t i = 0; i < mode_count; ++i) {
  ------------------
  |  Branch (82:24): [True: 3.18k, False: 687]
  ------------------
   83|  3.18k|      const auto mode = static_cast<PSK_Key_Exchange_Mode>(reader.get_byte());
   84|  3.18k|      if(mode == PSK_Key_Exchange_Mode::PSK_KE || mode == PSK_Key_Exchange_Mode::PSK_DHE_KE) {
  ------------------
  |  Branch (84:10): [True: 1.46k, False: 1.72k]
  |  Branch (84:51): [True: 460, False: 1.26k]
  ------------------
   85|  1.92k|         m_modes.push_back(mode);
   86|  1.92k|      }
   87|  3.18k|   }
   88|    687|}
_ZN5Botan3TLS23Certificate_AuthoritiesC2ERNS0_15TLS_Data_ReaderEt:
  106|    819|Certificate_Authorities::Certificate_Authorities(TLS_Data_Reader& reader, uint16_t extension_size) {
  107|    819|   if(extension_size < 2) {
  ------------------
  |  Branch (107:7): [True: 2, False: 817]
  ------------------
  108|      2|      throw Decoding_Error("Empty certificate_authorities extension is illegal");
  109|      2|   }
  110|       |
  111|    817|   const uint16_t purported_size = reader.get_uint16_t();
  112|       |
  113|    817|   if(reader.remaining_bytes() != purported_size) {
  ------------------
  |  Branch (113:7): [True: 30, False: 787]
  ------------------
  114|     30|      throw Decoding_Error("Inconsistent length in certificate_authorities extension");
  115|     30|   }
  116|       |
  117|       |   // RFC 8446 4.2.4: DistinguishedName authorities<3..2^16-1>;
  118|    787|   if(purported_size < 3) {
  ------------------
  |  Branch (118:7): [True: 2, False: 785]
  ------------------
  119|      2|      throw Decoding_Error("Empty certificate_authorities list is illegal");
  120|      2|   }
  121|       |
  122|  1.91k|   while(reader.has_remaining()) {
  ------------------
  |  Branch (122:10): [True: 1.13k, False: 785]
  ------------------
  123|       |      // RFC 8446 4.2.4: opaque DistinguishedName<1..2^16-1>
  124|  1.13k|      const std::vector<uint8_t> name_bits = reader.get_range<uint8_t>(2, 1, 65535);
  125|       |
  126|  1.13k|      BER_Decoder decoder(name_bits, BER_Decoder::Limits::DER());
  127|  1.13k|      m_distinguished_names.emplace_back();
  128|  1.13k|      decoder.decode(m_distinguished_names.back()).verify_end();
  129|  1.13k|   }
  130|    785|}
_ZN5Botan3TLS19EarlyDataIndicationC2ERNS0_15TLS_Data_ReaderEtNS0_14Handshake_TypeE:
  149|    285|                                         Handshake_Type message_type) {
  150|    285|   if(message_type == Handshake_Type::NewSessionTicket) {
  ------------------
  |  Branch (150:7): [True: 0, False: 285]
  ------------------
  151|      0|      if(extension_size != 4) {
  ------------------
  |  Branch (151:10): [True: 0, False: 0]
  ------------------
  152|      0|         throw TLS_Exception(Alert::DecodeError,
  153|      0|                             "Received an early_data extension in a NewSessionTicket message "
  154|      0|                             "without maximum early data size indication");
  155|      0|      }
  156|       |
  157|      0|      m_max_early_data_size = reader.get_uint32_t();
  158|    285|   } else if(extension_size != 0) {
  ------------------
  |  Branch (158:14): [True: 7, False: 278]
  ------------------
  159|      7|      throw TLS_Exception(Alert::DecodeError,
  160|      7|                          "Received an early_data extension containing an unexpected data "
  161|      7|                          "size indication");
  162|      7|   }
  163|    285|}
_ZNK5Botan3TLS19EarlyDataIndication5emptyEv:
  165|      5|bool EarlyDataIndication::empty() const {
  166|       |   // This extension may be empty by definition but still carry information
  167|      5|   return false;
  168|      5|}

_ZN5Botan3TLS9Key_ShareC2ERNS0_15TLS_Data_ReaderEtNS0_14Handshake_TypeE:
  376|  1.50k|Key_Share::Key_Share(TLS_Data_Reader& reader, uint16_t extension_size, Handshake_Type message_type) {
  377|  1.50k|   if(message_type == Handshake_Type::ClientHello) {
  ------------------
  |  Branch (377:7): [True: 1.02k, False: 478]
  ------------------
  378|  1.02k|      m_impl = std::make_unique<Key_Share_Impl>(Key_Share_ClientHello(reader, extension_size));
  379|  1.02k|   } else if(message_type == Handshake_Type::HelloRetryRequest) {
  ------------------
  |  Branch (379:14): [True: 0, False: 478]
  ------------------
  380|       |      // Connection_Side::Server
  381|      0|      m_impl = std::make_unique<Key_Share_Impl>(Key_Share_HelloRetryRequest(reader, extension_size));
  382|    478|   } else if(message_type == Handshake_Type::ServerHello) {
  ------------------
  |  Branch (382:14): [True: 474, False: 4]
  ------------------
  383|       |      // Connection_Side::Server
  384|    474|      m_impl = std::make_unique<Key_Share_Impl>(Key_Share_ServerHello(reader, extension_size));
  385|    474|   } else {
  386|      4|      throw Invalid_Argument(std::string("cannot create a Key_Share extension for message of type: ") +
  387|      4|                             handshake_type_to_string(message_type));
  388|      4|   }
  389|  1.50k|}
_ZN5Botan3TLS9Key_ShareD2Ev:
  408|  1.44k|Key_Share::~Key_Share() = default;
_ZNK5Botan3TLS9Key_Share5emptyEv:
  414|    152|bool Key_Share::empty() const {
  415|    152|   return std::visit([](const auto& key_share) { return key_share.empty(); }, m_impl->key_share);
  416|    152|}
_ZNK5Botan3TLS9Key_Share14offered_groupsEv:
  441|    233|std::vector<Named_Group> Key_Share::offered_groups() const {
  442|    233|   return std::visit([](const auto& keyshare) { return keyshare.offered_groups(); }, m_impl->key_share);
  443|    233|}
tls_extensions_key_share.cpp:_ZN5Botan3TLS12_GLOBAL__N_121Key_Share_ClientHelloC2ERNS0_15TLS_Data_ReaderEt:
  160|  1.02k|      Key_Share_ClientHello(TLS_Data_Reader& reader, uint16_t /* extension_size */) {
  161|       |         // The reader is per-extension (Extensions::deserialize binds it to
  162|       |         // exactly extension_size bytes). Enforce that the inner
  163|       |         // client_shares length matches what the outer extension has left,
  164|       |         // then let the entry loop consume everything; extn_reader's
  165|       |         // assert_done() at the deserialize call site catches any leftover.
  166|  1.02k|         const auto client_key_share_length = reader.get_uint16_t();
  167|  1.02k|         if(reader.remaining_bytes() != client_key_share_length) {
  ------------------
  |  Branch (167:13): [True: 21, False: 1.00k]
  ------------------
  168|     21|            throw TLS_Exception(Alert::DecodeError, "Inconsistent length in client KeyShare extension");
  169|     21|         }
  170|       |
  171|  1.00k|         std::unordered_set<uint16_t> seen_groups;
  172|  2.68k|         while(reader.has_remaining()) {
  ------------------
  |  Branch (172:16): [True: 1.68k, False: 995]
  ------------------
  173|       |            // Each KeyShareEntry is at least 4 bytes (group + 2-byte length).
  174|       |            // Cleaner failure than the reader underflow we'd otherwise hit
  175|       |            // when the inner buffer ends mid-entry.
  176|  1.68k|            if(reader.remaining_bytes() < 4) {
  ------------------
  |  Branch (176:16): [True: 7, False: 1.68k]
  ------------------
  177|      7|               throw TLS_Exception(Alert::DecodeError, "Not enough data to read another KeyShareEntry");
  178|      7|            }
  179|       |
  180|  1.68k|            Key_Share_Entry new_entry(reader);
  181|       |
  182|       |            // RFC 8446 4.2.8
  183|       |            //    Clients MUST NOT offer multiple KeyShareEntry values for the same
  184|       |            //    group. [...]
  185|       |            //    Servers MAY check for violations of these rules and abort the
  186|       |            //    handshake with an "illegal_parameter" alert if one is violated.
  187|  1.68k|            if(!seen_groups.insert(new_entry.group().wire_code()).second) {
  ------------------
  |  Branch (187:16): [True: 2, False: 1.67k]
  ------------------
  188|      2|               throw TLS_Exception(Alert::IllegalParameter, "Received multiple key share entries for the same group");
  189|      2|            }
  190|       |
  191|  1.67k|            m_client_shares.emplace_back(std::move(new_entry));
  192|  1.67k|         }
  193|  1.00k|      }
tls_extensions_key_share.cpp:_ZN5Botan3TLS12_GLOBAL__N_115Key_Share_EntryC2ERNS0_15TLS_Data_ReaderE:
   46|  2.15k|      explicit Key_Share_Entry(TLS_Data_Reader& reader) {
   47|       |         // TODO check that the group actually exists before casting...
   48|  2.15k|         m_group = static_cast<Named_Group>(reader.get_uint16_t());
   49|       |         // RFC 8446 4.2.8: opaque key_exchange<1..2^16-1>
   50|  2.15k|         m_key_exchange = reader.get_range<uint8_t>(2, 1, 65535);
   51|  2.15k|      }
tls_extensions_key_share.cpp:_ZNK5Botan3TLS12_GLOBAL__N_115Key_Share_Entry5groupEv:
   80|  1.96k|      Named_Group group() const { return m_group; }
tls_extensions_key_share.cpp:_ZN5Botan3TLS12_GLOBAL__N_121Key_Share_ClientHelloD2Ev:
  218|  2.95k|      ~Key_Share_ClientHello() = default;
tls_extensions_key_share.cpp:_ZN5Botan3TLS12_GLOBAL__N_121Key_Share_ServerHelloC2ERNS0_15TLS_Data_ReaderEt:
  120|    474|      Key_Share_ServerHello(TLS_Data_Reader& reader, uint16_t /*len*/) : m_server_share(reader) {}
tls_extensions_key_share.cpp:_ZN5Botan3TLS12_GLOBAL__N_121Key_Share_ServerHelloD2Ev:
  128|  1.38k|      ~Key_Share_ServerHello() = default;
tls_extensions_key_share.cpp:_ZZNK5Botan3TLS9Key_Share5emptyEvENK3$_0clINS0_12_GLOBAL__N_121Key_Share_ServerHelloEEEDaRKT_:
  415|    152|   return std::visit([](const auto& key_share) { return key_share.empty(); }, m_impl->key_share);
tls_extensions_key_share.cpp:_ZNK5Botan3TLS12_GLOBAL__N_121Key_Share_ServerHello5emptyEv:
  138|    152|      bool empty() const { return m_server_share.empty(); }
tls_extensions_key_share.cpp:_ZNK5Botan3TLS12_GLOBAL__N_115Key_Share_Entry5emptyEv:
   66|    152|      bool empty() const { return (m_group == Group_Params::NONE) && m_key_exchange.empty(); }
  ------------------
  |  Branch (66:35): [True: 66, False: 86]
  |  Branch (66:70): [True: 0, False: 66]
  ------------------
tls_extensions_key_share.cpp:_ZZNK5Botan3TLS9Key_Share14offered_groupsEvENK3$_0clINS0_12_GLOBAL__N_121Key_Share_ClientHelloEEEDaRKT_:
  442|    233|   return std::visit([](const auto& keyshare) { return keyshare.offered_groups(); }, m_impl->key_share);
tls_extensions_key_share.cpp:_ZNK5Botan3TLS12_GLOBAL__N_121Key_Share_ClientHello14offered_groupsEv:
  240|    233|      std::vector<Named_Group> offered_groups() const {
  241|    233|         std::vector<Named_Group> offered_groups;
  242|    233|         offered_groups.reserve(m_client_shares.size());
  243|    290|         for(const auto& share : m_client_shares) {
  ------------------
  |  Branch (243:32): [True: 290, False: 233]
  ------------------
  244|    290|            offered_groups.push_back(share.group());
  245|    290|         }
  246|    233|         return offered_groups;
  247|    233|      }
tls_extensions_key_share.cpp:_ZN5Botan3TLS12_GLOBAL__N_121Key_Share_ClientHelloC2EOS2_:
  223|  1.96k|      Key_Share_ClientHello(Key_Share_ClientHello&&) = default;
tls_extensions_key_share.cpp:_ZN5Botan3TLS9Key_Share14Key_Share_ImplC2ENSt3__17variantIJNS0_12_GLOBAL__N_121Key_Share_ClientHelloENS5_21Key_Share_ServerHelloENS5_27Key_Share_HelloRetryRequestEEEE:
  371|  1.44k|      explicit Key_Share_Impl(Key_Share_Type ks) : key_share(std::move(ks)) {}
tls_extensions_key_share.cpp:_ZN5Botan3TLS12_GLOBAL__N_121Key_Share_ServerHelloC2EOS2_:
  133|    922|      Key_Share_ServerHello(Key_Share_ServerHello&&) = default;

_ZN5Botan3TLS3PSKC2ERNS0_15TLS_Data_ReaderEtNS0_14Handshake_TypeE:
  142|  1.28k|PSK::PSK(TLS_Data_Reader& reader, uint16_t extension_size, Handshake_Type message_type) {
  143|  1.28k|   if(message_type == Handshake_Type::ServerHello) {
  ------------------
  |  Branch (143:7): [True: 792, False: 493]
  ------------------
  144|    792|      if(extension_size != 2) {
  ------------------
  |  Branch (144:10): [True: 1, False: 791]
  ------------------
  145|      1|         throw TLS_Exception(Alert::DecodeError, "Server provided a malformed PSK extension");
  146|      1|      }
  147|       |
  148|    791|      const uint16_t selected_id = reader.get_uint16_t();
  149|    791|      m_impl = std::make_unique<PSK_Internal>(Server_PSK(selected_id));
  150|    791|   } else if(message_type == Handshake_Type::ClientHello) {
  ------------------
  |  Branch (150:14): [True: 488, False: 5]
  ------------------
  151|    488|      const auto identities_length = reader.get_uint16_t();
  152|    488|      const auto identities_offset = reader.read_so_far();
  153|       |
  154|    488|      std::vector<PskIdentity> psk_identities;
  155|  3.56k|      while(reader.has_remaining() && (reader.read_so_far() - identities_offset) < identities_length) {
  ------------------
  |  Branch (155:13): [True: 3.50k, False: 54]
  |  Branch (155:39): [True: 3.07k, False: 434]
  ------------------
  156|       |         /* Per RFC 8446 PskIdentity is
  157|       |
  158|       |         struct {
  159|       |            opaque identity<1..2^16-1>;
  160|       |            uint32 obfuscated_ticket_age;
  161|       |         } PskIdentity;
  162|       |
  163|       |         so we should reject an empty identity. However BoGo seems to expect
  164|       |         being able to send us such an identity, so for now we accept it.
  165|       |         */
  166|       |
  167|  3.07k|         auto identity = reader.get_tls_length_value(2);
  168|  3.07k|         const auto obfuscated_ticket_age = reader.get_uint32_t();
  169|  3.07k|         psk_identities.emplace_back(std::move(identity), obfuscated_ticket_age);
  170|  3.07k|      }
  171|       |
  172|    488|      if(psk_identities.empty()) {
  ------------------
  |  Branch (172:10): [True: 1, False: 487]
  ------------------
  173|      1|         throw TLS_Exception(Alert::DecodeError, "Empty PSK list");
  174|      1|      }
  175|       |
  176|    487|      if(reader.read_so_far() - identities_offset != identities_length) {
  ------------------
  |  Branch (176:10): [True: 32, False: 455]
  ------------------
  177|     32|         throw TLS_Exception(Alert::DecodeError, "Inconsistent PSK identity list");
  178|     32|      }
  179|       |
  180|    455|      const auto binders_length = reader.get_uint16_t();
  181|    455|      const auto binders_offset = reader.read_so_far();
  182|       |
  183|    455|      if(binders_length == 0) {
  ------------------
  |  Branch (183:10): [True: 1, False: 454]
  ------------------
  184|      1|         throw TLS_Exception(Alert::DecodeError, "Empty PSK binders list");
  185|      1|      }
  186|       |
  187|    454|      std::vector<Client_PSK> psks;
  188|  2.22k|      for(auto& psk_identity : psk_identities) {
  ------------------
  |  Branch (188:30): [True: 2.22k, False: 446]
  ------------------
  189|  2.22k|         if(!reader.has_remaining() || reader.read_so_far() - binders_offset >= binders_length) {
  ------------------
  |  Branch (189:13): [True: 7, False: 2.22k]
  |  Branch (189:40): [True: 1, False: 2.22k]
  ------------------
  190|      8|            throw TLS_Exception(Alert::IllegalParameter, "Not enough PSK binders");
  191|      8|         }
  192|       |
  193|       |         // RFC 8446 4.2.11 declares PskBinderEntry opaque<32..255>, but we accept any
  194|       |         // 0..255 length here and let validate_binder reject, which yields a bad_record_mac
  195|       |         // alert rather than decode_error. BoringSSL behaves the same way and BoGo has
  196|       |         // tests that specifically expect this.
  197|       |
  198|  2.22k|         psks.emplace_back(std::move(psk_identity), reader.get_tls_length_value(1));
  199|  2.22k|      }
  200|       |
  201|    446|      if(reader.read_so_far() - binders_offset != binders_length) {
  ------------------
  |  Branch (201:10): [True: 39, False: 407]
  ------------------
  202|     39|         throw TLS_Exception(Alert::IllegalParameter, "Too many PSK binders");
  203|     39|      }
  204|       |
  205|    407|      m_impl = std::make_unique<PSK_Internal>(std::move(psks));
  206|    407|   } else {
  207|      5|      throw TLS_Exception(Alert::DecodeError, "Found a PSK extension in an unexpected handshake message");
  208|      5|   }
  209|  1.28k|}
_ZN5Botan3TLS3PSKD2Ev:
  231|  1.15k|PSK::~PSK() = default;
_ZNK5Botan3TLS3PSK5emptyEv:
  233|    372|bool PSK::empty() const {
  234|    372|   if(std::holds_alternative<Server_PSK>(m_impl->psk)) {
  ------------------
  |  Branch (234:7): [True: 372, False: 0]
  ------------------
  235|    372|      return false;
  236|    372|   }
  237|       |
  238|      0|   BOTAN_ASSERT_NOMSG(std::holds_alternative<std::vector<Client_PSK>>(m_impl->psk));
  ------------------
  |  |   84|      0|   do {                                                                     \
  |  |   85|      0|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|      0|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 0]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 0]
  |  |  ------------------
  ------------------
  239|      0|   return std::get<std::vector<Client_PSK>>(m_impl->psk).empty();
  240|    372|}
tls_extensions_psk.cpp:_ZN5Botan3TLS12_GLOBAL__N_110Server_PSKC2Et:
  109|    791|      explicit Server_PSK(uint16_t id) : m_selected_identity(id), m_session_to_resume_or_psk(std::monostate()) {}
tls_extensions_psk.cpp:_ZN5Botan3TLS12_GLOBAL__N_110Client_PSKC2ENS0_11PskIdentityENSt3__16vectorIhNS4_9allocatorIhEEEE:
   56|  2.21k|            m_identity(std::move(id)), m_binder(std::move(bndr)), m_is_resumption(false) {}
tls_extensions_psk.cpp:_ZN5Botan3TLS3PSK12PSK_InternalC2ENS0_12_GLOBAL__N_110Server_PSKE:
  134|    791|      explicit PSK_Internal(Server_PSK srv_psk) : psk(std::move(srv_psk)) {}
tls_extensions_psk.cpp:_ZN5Botan3TLS3PSK12PSK_InternalC2ENSt3__16vectorINS0_12_GLOBAL__N_110Client_PSKENS3_9allocatorIS6_EEEE:
  136|    362|      explicit PSK_Internal(std::vector<Client_PSK> clt_psks) : psk(std::move(clt_psks)) {}

_ZN5Botan3TLS15Handshake_Layer9copy_dataENSt3__14spanIKhLm18446744073709551615EEE:
   22|  7.70k|void Handshake_Layer::copy_data(std::span<const uint8_t> data_from_peer) {
   23|       |   // Compact consumed data before appending new data
   24|  7.70k|   BOTAN_ASSERT_NOMSG(m_read_offset <= m_read_buffer.size());
  ------------------
  |  |   84|  7.70k|   do {                                                                     \
  |  |   85|  7.70k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  7.70k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 7.70k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  7.70k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 7.70k]
  |  |  ------------------
  ------------------
   25|  7.70k|   if(m_read_offset > 0) {
  ------------------
  |  Branch (25:7): [True: 0, False: 7.70k]
  ------------------
   26|      0|      m_read_buffer.erase(m_read_buffer.begin(), m_read_buffer.begin() + m_read_offset);
   27|      0|      m_read_offset = 0;
   28|      0|   }
   29|       |
   30|  7.70k|   m_read_buffer.insert(m_read_buffer.end(), data_from_peer.begin(), data_from_peer.end());
   31|  7.70k|}
_ZN5Botan3TLS15Handshake_Layer12next_messageERKNS0_6PolicyERNS0_21Transcript_Hash_StateE:
  141|  34.6k|                                                                  Transcript_Hash_State& transcript_hash) {
  142|  34.6k|   BOTAN_ASSERT_NOMSG(m_read_offset <= m_read_buffer.size());
  ------------------
  |  |   84|  34.6k|   do {                                                                     \
  |  |   85|  34.6k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  34.6k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 34.6k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  34.6k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 34.6k]
  |  |  ------------------
  ------------------
  143|  34.6k|   auto pending = std::span<const uint8_t>{m_read_buffer}.subspan(m_read_offset);
  144|  34.6k|   TLS::TLS_Data_Reader reader("handshake message", pending);
  145|       |
  146|  34.6k|   auto msg = parse_message<Handshake_Message_13>(reader, policy, m_peer, m_certificate_type);
  147|  34.6k|   if(msg.has_value()) {
  ------------------
  |  Branch (147:7): [True: 28.2k, False: 6.36k]
  ------------------
  148|  28.2k|      transcript_hash.update(pending.first(reader.read_so_far()));
  149|  28.2k|      m_read_offset += reader.read_so_far();
  150|  28.2k|      BOTAN_ASSERT_NOMSG(m_read_offset <= m_read_buffer.size());
  ------------------
  |  |   84|  28.2k|   do {                                                                     \
  |  |   85|  28.2k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  28.2k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 28.2k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  28.2k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 28.2k]
  |  |  ------------------
  ------------------
  151|       |
  152|  28.2k|      if(m_read_offset == m_read_buffer.size()) {
  ------------------
  |  Branch (152:10): [True: 1.13k, False: 27.1k]
  ------------------
  153|  1.13k|         m_read_buffer.clear();
  154|  1.13k|         m_read_offset = 0;
  155|  1.13k|      }
  156|  28.2k|   }
  157|       |
  158|  34.6k|   return msg;
  159|  34.6k|}
_ZN5Botan3TLS15Handshake_Layer27next_post_handshake_messageERKNS0_6PolicyE:
  161|  1.28k|std::optional<Post_Handshake_Message_13> Handshake_Layer::next_post_handshake_message(const Policy& policy) {
  162|  1.28k|   BOTAN_ASSERT_NOMSG(m_read_offset <= m_read_buffer.size());
  ------------------
  |  |   84|  1.28k|   do {                                                                     \
  |  |   85|  1.28k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  1.28k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 1.28k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  1.28k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 1.28k]
  |  |  ------------------
  ------------------
  163|  1.28k|   auto pending = std::span<const uint8_t>{m_read_buffer}.subspan(m_read_offset);
  164|  1.28k|   TLS::TLS_Data_Reader reader("post handshake message", pending);
  165|       |
  166|  1.28k|   auto msg = parse_message<Post_Handshake_Message_13>(reader, policy, m_peer, m_certificate_type);
  167|  1.28k|   if(msg.has_value()) {
  ------------------
  |  Branch (167:7): [True: 0, False: 1.28k]
  ------------------
  168|      0|      m_read_offset += reader.read_so_far();
  169|      0|      BOTAN_ASSERT_NOMSG(m_read_offset <= m_read_buffer.size());
  ------------------
  |  |   84|      0|   do {                                                                     \
  |  |   85|      0|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|      0|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 0]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 0]
  |  |  ------------------
  ------------------
  170|       |
  171|      0|      if(m_read_offset == m_read_buffer.size()) {
  ------------------
  |  Branch (171:10): [True: 0, False: 0]
  ------------------
  172|      0|         m_read_buffer.clear();
  173|      0|         m_read_offset = 0;
  174|      0|      }
  175|      0|   }
  176|       |
  177|  1.28k|   return msg;
  178|  1.28k|}
tls_handshake_layer_13.cpp:_ZN5Botan3TLS12_GLOBAL__N_113parse_messageINSt3__17variantIJNS0_15Client_Hello_13ENS0_20Client_Hello_12_ShimENS0_15Server_Hello_13ENS0_20Server_Hello_12_ShimENS0_19Hello_Retry_RequestENS0_20Encrypted_ExtensionsENS0_14Certificate_13ENS0_22Certificate_Request_13ENS0_21Certificate_Verify_13ENS0_11Finished_13EEEEEENS3_8optionalIT_EERNS0_15TLS_Data_ReaderERKNS0_6PolicyENS0_15Connection_SideENS0_16Certificate_TypeE:
   78|  34.6k|                                      const Certificate_Type cert_type) {
   79|       |   // read the message header
   80|  34.6k|   if(reader.remaining_bytes() < HEADER_LENGTH) {
  ------------------
  |  Branch (80:7): [True: 1.23k, False: 33.3k]
  ------------------
   81|  1.23k|      return std::nullopt;
   82|  1.23k|   }
   83|       |
   84|  33.3k|   const Handshake_Type type = handshake_type_from_byte<Msg_Type>(reader.get_byte());
   85|       |
   86|       |   // make sure we have received the full message
   87|  33.3k|   const size_t msg_len = reader.get_uint24_t();
   88|       |
   89|       |   // TODO(Botan4) this is split out due to a GCC 11 ICE, can be inlined
   90|  33.3k|   verify_handshake_message_size(msg_len, policy.maximum_handshake_message_size());
   91|       |
   92|  33.3k|   if(reader.remaining_bytes() < msg_len) {
  ------------------
  |  Branch (92:7): [True: 48, False: 33.3k]
  ------------------
   93|     48|      return std::nullopt;
   94|     48|   }
   95|       |
   96|       |   // create the message
   97|  33.3k|   const auto msg = reader.get_fixed<uint8_t>(msg_len);
   98|  33.3k|   if constexpr(std::is_same_v<Msg_Type, Handshake_Message_13>) {
   99|  33.3k|      switch(type) {
  100|       |         // Client Hello and Server Hello messages are ambiguous. Both may come
  101|       |         // from non-TLS 1.3 peers. Hence, their parsing is somewhat different.
  102|  6.01k|         case Handshake_Type::ClientHello:
  ------------------
  |  Branch (102:10): [True: 6.01k, False: 27.3k]
  ------------------
  103|       |            // ... might be TLS 1.2 Client Hello or TLS 1.3 Client Hello
  104|  6.01k|            return generalize_to<Handshake_Message_13>(Client_Hello_13::parse(msg));
  105|  4.31k|         case Handshake_Type::ServerHello:
  ------------------
  |  Branch (105:10): [True: 4.31k, False: 29.0k]
  ------------------
  106|       |            // ... might be TLS 1.2 Server Hello or TLS 1.3 Server Hello or
  107|       |            // a TLS 1.3 Hello Retry Request disguising as a Server Hello
  108|  4.31k|            return generalize_to<Handshake_Message_13>(Server_Hello_13::parse(msg));
  109|       |         // case Handshake_Type::EndOfEarlyData:
  110|       |         //    return End_Of_Early_Data(msg);
  111|  7.16k|         case Handshake_Type::EncryptedExtensions:
  ------------------
  |  Branch (111:10): [True: 7.16k, False: 26.1k]
  ------------------
  112|  7.16k|            return Encrypted_Extensions(msg);
  113|  2.97k|         case Handshake_Type::Certificate:
  ------------------
  |  Branch (113:10): [True: 2.97k, False: 30.3k]
  ------------------
  114|  2.97k|            return Certificate_13(msg, policy, peer_side, cert_type);
  115|  1.68k|         case Handshake_Type::CertificateRequest:
  ------------------
  |  Branch (115:10): [True: 1.68k, False: 31.6k]
  ------------------
  116|  1.68k|            return Certificate_Request_13(msg, peer_side);
  117|  2.50k|         case Handshake_Type::CertificateVerify:
  ------------------
  |  Branch (117:10): [True: 2.50k, False: 30.8k]
  ------------------
  118|  2.50k|            return Certificate_Verify_13(msg, peer_side);
  119|  8.62k|         case Handshake_Type::Finished:
  ------------------
  |  Branch (119:10): [True: 8.62k, False: 24.7k]
  ------------------
  120|  8.62k|            return Finished_13(msg);
  121|      0|         default:
  ------------------
  |  Branch (121:10): [True: 0, False: 33.3k]
  ------------------
  122|      0|            BOTAN_ASSERT(false, "cannot be reached");  // make sure to update handshake_type_from_byte
  ------------------
  |  |   71|      0|   do {                                                                                 \
  |  |   72|      0|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                     \
  |  |   73|      0|      if(!(expr)) {                                                                     \
  |  |  ------------------
  |  |  |  Branch (73:10): [True: 0, Folded]
  |  |  ------------------
  |  |   74|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                            \
  |  |   75|      0|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   76|      0|      }                                                                                 \
  |  |   77|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (77:12): [Folded, False: 0]
  |  |  ------------------
  ------------------
  123|  33.3k|      }
  124|       |   } else {
  125|       |      BOTAN_UNUSED(peer_side);
  126|       |
  127|       |      switch(type) {
  128|       |         case Handshake_Type::NewSessionTicket:
  129|       |            return New_Session_Ticket_13(msg, peer_side);
  130|       |         case Handshake_Type::KeyUpdate:
  131|       |            return Key_Update(msg);
  132|       |         default:
  133|       |            BOTAN_ASSERT(false, "cannot be reached");  // make sure to update handshake_type_from_byte
  134|       |      }
  135|       |   }
  136|  33.3k|}
tls_handshake_layer_13.cpp:_ZN5Botan3TLS12_GLOBAL__N_124handshake_type_from_byteINSt3__17variantIJNS0_15Client_Hello_13ENS0_20Client_Hello_12_ShimENS0_15Server_Hello_13ENS0_20Server_Hello_12_ShimENS0_19Hello_Retry_RequestENS0_20Encrypted_ExtensionsENS0_14Certificate_13ENS0_22Certificate_Request_13ENS0_21Certificate_Verify_13ENS0_11Finished_13EEEEEENS0_14Handshake_TypeEh:
   38|  33.3k|Handshake_Type handshake_type_from_byte(uint8_t byte_value) {
   39|  33.3k|   const auto type = static_cast<Handshake_Type>(byte_value);
   40|       |
   41|  33.3k|   if constexpr(std::is_same_v<Msg_Type, Handshake_Message_13>) {
   42|  33.3k|      switch(type) {
   43|  6.04k|         case Handshake_Type::ClientHello:
  ------------------
  |  Branch (43:10): [True: 6.04k, False: 27.3k]
  ------------------
   44|  10.3k|         case Handshake_Type::ServerHello:
  ------------------
  |  Branch (44:10): [True: 4.33k, False: 29.0k]
  ------------------
   45|       |         // case Handshake_Type::EndOfEarlyData:  // NYI: needs PSK/resumption support -- won't be offered in Client Hello for now
   46|  17.5k|         case Handshake_Type::EncryptedExtensions:
  ------------------
  |  Branch (46:10): [True: 7.17k, False: 26.2k]
  ------------------
   47|  20.5k|         case Handshake_Type::Certificate:
  ------------------
  |  Branch (47:10): [True: 2.99k, False: 30.4k]
  ------------------
   48|  22.2k|         case Handshake_Type::CertificateRequest:
  ------------------
  |  Branch (48:10): [True: 1.68k, False: 31.7k]
  ------------------
   49|  24.7k|         case Handshake_Type::CertificateVerify:
  ------------------
  |  Branch (49:10): [True: 2.50k, False: 30.8k]
  ------------------
   50|  33.3k|         case Handshake_Type::Finished:
  ------------------
  |  Branch (50:10): [True: 8.62k, False: 24.7k]
  ------------------
   51|  33.3k|            return type;
   52|     30|         default:
  ------------------
  |  Branch (52:10): [True: 30, False: 33.3k]
  ------------------
   53|     30|            throw TLS_Exception(AlertType::UnexpectedMessage, "Unknown handshake message received");
   54|  33.3k|      }
   55|       |   } else {
   56|       |      switch(type) {
   57|       |         case Handshake_Type::NewSessionTicket:
   58|       |         case Handshake_Type::KeyUpdate:
   59|       |            // case Handshake_Type::CertificateRequest:  // NYI: post-handshake client auth (RFC 8446 4.6.2) -- won't be offered in Client Hello for now
   60|       |            return type;
   61|       |         default:
   62|       |            throw TLS_Exception(AlertType::UnexpectedMessage, "Unknown post-handshake message received");
   63|       |      }
   64|       |   }
   65|  33.3k|}
tls_handshake_layer_13.cpp:_ZN5Botan3TLS12_GLOBAL__N_129verify_handshake_message_sizeEmm:
   67|  33.3k|void verify_handshake_message_size(size_t msg_len, size_t max_size) {
   68|  33.3k|   if(max_size > 0 && msg_len > max_size) {
  ------------------
  |  Branch (68:7): [True: 33.3k, False: 0]
  |  Branch (68:23): [True: 38, False: 33.3k]
  ------------------
   69|     38|      throw TLS_Exception(Alert::HandshakeFailure,
   70|     38|                          Botan::fmt("Handshake message is {} bytes, policy maximum is {}", msg_len, max_size));
   71|     38|   }
   72|  33.3k|}
tls_handshake_layer_13.cpp:_ZN5Botan3TLS12_GLOBAL__N_113parse_messageINSt3__17variantIJNS0_21New_Session_Ticket_13ENS0_10Key_UpdateEEEEEENS3_8optionalIT_EERNS0_15TLS_Data_ReaderERKNS0_6PolicyENS0_15Connection_SideENS0_16Certificate_TypeE:
   78|  1.28k|                                      const Certificate_Type cert_type) {
   79|       |   // read the message header
   80|  1.28k|   if(reader.remaining_bytes() < HEADER_LENGTH) {
  ------------------
  |  Branch (80:7): [True: 3, False: 1.28k]
  ------------------
   81|      3|      return std::nullopt;
   82|      3|   }
   83|       |
   84|  1.28k|   const Handshake_Type type = handshake_type_from_byte<Msg_Type>(reader.get_byte());
   85|       |
   86|       |   // make sure we have received the full message
   87|  1.28k|   const size_t msg_len = reader.get_uint24_t();
   88|       |
   89|       |   // TODO(Botan4) this is split out due to a GCC 11 ICE, can be inlined
   90|  1.28k|   verify_handshake_message_size(msg_len, policy.maximum_handshake_message_size());
   91|       |
   92|  1.28k|   if(reader.remaining_bytes() < msg_len) {
  ------------------
  |  Branch (92:7): [True: 0, False: 1.28k]
  ------------------
   93|      0|      return std::nullopt;
   94|      0|   }
   95|       |
   96|       |   // create the message
   97|  1.28k|   const auto msg = reader.get_fixed<uint8_t>(msg_len);
   98|       |   if constexpr(std::is_same_v<Msg_Type, Handshake_Message_13>) {
   99|       |      switch(type) {
  100|       |         // Client Hello and Server Hello messages are ambiguous. Both may come
  101|       |         // from non-TLS 1.3 peers. Hence, their parsing is somewhat different.
  102|       |         case Handshake_Type::ClientHello:
  103|       |            // ... might be TLS 1.2 Client Hello or TLS 1.3 Client Hello
  104|       |            return generalize_to<Handshake_Message_13>(Client_Hello_13::parse(msg));
  105|       |         case Handshake_Type::ServerHello:
  106|       |            // ... might be TLS 1.2 Server Hello or TLS 1.3 Server Hello or
  107|       |            // a TLS 1.3 Hello Retry Request disguising as a Server Hello
  108|       |            return generalize_to<Handshake_Message_13>(Server_Hello_13::parse(msg));
  109|       |         // case Handshake_Type::EndOfEarlyData:
  110|       |         //    return End_Of_Early_Data(msg);
  111|       |         case Handshake_Type::EncryptedExtensions:
  112|       |            return Encrypted_Extensions(msg);
  113|       |         case Handshake_Type::Certificate:
  114|       |            return Certificate_13(msg, policy, peer_side, cert_type);
  115|       |         case Handshake_Type::CertificateRequest:
  116|       |            return Certificate_Request_13(msg, peer_side);
  117|       |         case Handshake_Type::CertificateVerify:
  118|       |            return Certificate_Verify_13(msg, peer_side);
  119|       |         case Handshake_Type::Finished:
  120|       |            return Finished_13(msg);
  121|       |         default:
  122|       |            BOTAN_ASSERT(false, "cannot be reached");  // make sure to update handshake_type_from_byte
  123|       |      }
  124|  1.28k|   } else {
  125|  1.28k|      BOTAN_UNUSED(peer_side);
  ------------------
  |  |  151|  1.28k|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
  126|       |
  127|  1.28k|      switch(type) {
  128|      0|         case Handshake_Type::NewSessionTicket:
  ------------------
  |  Branch (128:10): [True: 0, False: 1.28k]
  ------------------
  129|      0|            return New_Session_Ticket_13(msg, peer_side);
  130|      0|         case Handshake_Type::KeyUpdate:
  ------------------
  |  Branch (130:10): [True: 0, False: 1.28k]
  ------------------
  131|      0|            return Key_Update(msg);
  132|      0|         default:
  ------------------
  |  Branch (132:10): [True: 0, False: 1.28k]
  ------------------
  133|      0|            BOTAN_ASSERT(false, "cannot be reached");  // make sure to update handshake_type_from_byte
  ------------------
  |  |   71|      0|   do {                                                                                 \
  |  |   72|      0|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                     \
  |  |   73|      0|      if(!(expr)) {                                                                     \
  |  |  ------------------
  |  |  |  Branch (73:10): [True: 0, Folded]
  |  |  ------------------
  |  |   74|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                            \
  |  |   75|      0|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   76|      0|      }                                                                                 \
  |  |   77|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (77:12): [Folded, False: 0]
  |  |  ------------------
  ------------------
  134|  1.28k|      }
  135|  1.28k|   }
  136|  1.28k|}
tls_handshake_layer_13.cpp:_ZN5Botan3TLS12_GLOBAL__N_124handshake_type_from_byteINSt3__17variantIJNS0_21New_Session_Ticket_13ENS0_10Key_UpdateEEEEEENS0_14Handshake_TypeEh:
   38|  1.28k|Handshake_Type handshake_type_from_byte(uint8_t byte_value) {
   39|  1.28k|   const auto type = static_cast<Handshake_Type>(byte_value);
   40|       |
   41|       |   if constexpr(std::is_same_v<Msg_Type, Handshake_Message_13>) {
   42|       |      switch(type) {
   43|       |         case Handshake_Type::ClientHello:
   44|       |         case Handshake_Type::ServerHello:
   45|       |         // case Handshake_Type::EndOfEarlyData:  // NYI: needs PSK/resumption support -- won't be offered in Client Hello for now
   46|       |         case Handshake_Type::EncryptedExtensions:
   47|       |         case Handshake_Type::Certificate:
   48|       |         case Handshake_Type::CertificateRequest:
   49|       |         case Handshake_Type::CertificateVerify:
   50|       |         case Handshake_Type::Finished:
   51|       |            return type;
   52|       |         default:
   53|       |            throw TLS_Exception(AlertType::UnexpectedMessage, "Unknown handshake message received");
   54|       |      }
   55|  1.28k|   } else {
   56|  1.28k|      switch(type) {
   57|      0|         case Handshake_Type::NewSessionTicket:
  ------------------
  |  Branch (57:10): [True: 0, False: 1.28k]
  ------------------
   58|      0|         case Handshake_Type::KeyUpdate:
  ------------------
  |  Branch (58:10): [True: 0, False: 1.28k]
  ------------------
   59|       |            // case Handshake_Type::CertificateRequest:  // NYI: post-handshake client auth (RFC 8446 4.6.2) -- won't be offered in Client Hello for now
   60|      0|            return type;
   61|  1.28k|         default:
  ------------------
  |  Branch (61:10): [True: 1.28k, False: 0]
  ------------------
   62|  1.28k|            throw TLS_Exception(AlertType::UnexpectedMessage, "Unknown post-handshake message received");
   63|  1.28k|      }
   64|  1.28k|   }
   65|  1.28k|}

_ZN5Botan3TLS21Transcript_Hash_StateC2ENSt3__117basic_string_viewIcNS2_11char_traitsIcEEEE:
   20|  6.42k|Transcript_Hash_State::Transcript_Hash_State(std::string_view algo_spec) {
   21|  6.42k|   set_algorithm(algo_spec);
   22|  6.42k|}
_ZN5Botan3TLS21Transcript_Hash_StateD2Ev:
   26|  6.42k|Transcript_Hash_State::~Transcript_Hash_State() = default;
_ZN5Botan3TLS21Transcript_Hash_State6updateENSt3__14spanIKhLm18446744073709551615EEE:
  155|  28.2k|void Transcript_Hash_State::update(std::span<const uint8_t> serialized_message_s) {
  156|  28.2k|   const auto* serialized_message = serialized_message_s.data();
  157|  28.2k|   auto serialized_message_length = serialized_message_s.size();
  158|  28.2k|   if(m_hash != nullptr) {
  ------------------
  |  Branch (158:7): [True: 28.2k, False: 0]
  ------------------
  159|  28.2k|      auto truncation_mark = serialized_message_length;
  160|       |
  161|       |      // Check whether we should generate a truncated hash for supporting PSK
  162|       |      // binder calculation or verification. See RFC 8446 4.2.11.2.
  163|  28.2k|      if(serialized_message_length > 0 && *serialized_message == static_cast<uint8_t>(Handshake_Type::ClientHello)) {
  ------------------
  |  Branch (163:10): [True: 28.2k, False: 0]
  |  Branch (163:43): [True: 5.47k, False: 22.7k]
  ------------------
  164|  5.47k|         truncation_mark = find_client_hello_truncation_mark(serialized_message_s);
  165|  5.47k|      }
  166|       |
  167|  28.2k|      if(truncation_mark < serialized_message_length) {
  ------------------
  |  Branch (167:10): [True: 718, False: 27.5k]
  ------------------
  168|    718|         m_hash->update(serialized_message, truncation_mark);
  169|    718|         m_truncated = read_hash_state(m_hash);
  170|    718|         m_hash->update(serialized_message + truncation_mark, serialized_message_length - truncation_mark);
  171|  27.5k|      } else {
  172|  27.5k|         m_truncated.clear();
  173|  27.5k|         m_hash->update(serialized_message, serialized_message_length);
  174|  27.5k|      }
  175|       |
  176|  28.2k|      m_previous = std::exchange(m_current, read_hash_state(m_hash));
  177|  28.2k|   } else {
  178|      0|      m_unprocessed_transcript.push_back(
  179|      0|         std::vector(serialized_message, serialized_message + serialized_message_length));
  180|      0|   }
  181|  28.2k|}
_ZN5Botan3TLS21Transcript_Hash_State13set_algorithmENSt3__117basic_string_viewIcNS2_11char_traitsIcEEEE:
  198|  6.42k|void Transcript_Hash_State::set_algorithm(std::string_view algo_spec) {
  199|  6.42k|   BOTAN_STATE_CHECK(m_hash == nullptr || m_hash->name() == algo_spec);
  ------------------
  |  |   51|  6.42k|   do {                                                         \
  |  |   52|  6.42k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */             \
  |  |   53|  6.42k|      if(!(expr)) {                                             \
  |  |  ------------------
  |  |  |  Branch (53:10): [True: 0, False: 6.42k]
  |  |  |  Branch (53:12): [True: 6.42k, False: 0]
  |  |  |  Branch (53:12): [True: 0, False: 0]
  |  |  ------------------
  |  |   54|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */    \
  |  |   55|      0|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   56|      0|      }                                                         \
  |  |   57|  6.42k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (57:12): [Folded, False: 6.42k]
  |  |  ------------------
  ------------------
  200|  6.42k|   if(m_hash != nullptr) {
  ------------------
  |  Branch (200:7): [True: 0, False: 6.42k]
  ------------------
  201|      0|      return;
  202|      0|   }
  203|       |
  204|  6.42k|   m_hash = HashFunction::create_or_throw(algo_spec);
  205|  6.42k|   for(const auto& msg : m_unprocessed_transcript) {
  ------------------
  |  Branch (205:24): [True: 0, False: 6.42k]
  ------------------
  206|      0|      update(msg);
  207|      0|   }
  208|  6.42k|   m_unprocessed_transcript.clear();
  209|  6.42k|}
tls_transcript_hash_13.cpp:_ZN5Botan3TLS12_GLOBAL__N_133find_client_hello_truncation_markENSt3__14spanIKhLm18446744073709551615EEE:
   84|  5.47k|size_t find_client_hello_truncation_mark(std::span<const uint8_t> client_hello) {
   85|  5.47k|   TLS_Data_Reader reader("Client Hello Truncation", client_hello);
   86|       |
   87|       |   // handshake message type
   88|  5.47k|   BOTAN_ASSERT_NOMSG(reader.get_byte() == static_cast<uint8_t>(Handshake_Type::ClientHello));
  ------------------
  |  |   84|  5.47k|   do {                                                                     \
  |  |   85|  5.47k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  5.47k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 5.47k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  5.47k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 5.47k]
  |  |  ------------------
  ------------------
   89|       |
   90|       |   // message length
   91|  5.47k|   reader.discard_next(3);
   92|       |
   93|       |   // legacy version
   94|  5.47k|   reader.discard_next(2);
   95|       |
   96|       |   // random
   97|  5.47k|   reader.discard_next(32);
   98|       |
   99|       |   // session ID
  100|  5.47k|   const auto session_id_length = reader.get_byte();
  101|  5.47k|   reader.discard_next(session_id_length);
  102|       |
  103|       |   // TODO: DTLS contains a hello_cookie in this location
  104|       |   //       Currently we don't support DTLS 1.3
  105|       |
  106|       |   // cipher suites
  107|  5.47k|   const auto ciphersuites_length = reader.get_uint16_t();
  108|  5.47k|   reader.discard_next(ciphersuites_length);
  109|       |
  110|       |   // compression methods
  111|  5.47k|   const auto compression_methods_length = reader.get_byte();
  112|  5.47k|   reader.discard_next(compression_methods_length);
  113|       |
  114|       |   // extensions
  115|  5.47k|   const auto extensions_length = reader.get_uint16_t();
  116|  5.47k|   const auto extensions_offset = reader.read_so_far();
  117|  10.9k|   while(reader.has_remaining() && reader.read_so_far() - extensions_offset < extensions_length) {
  ------------------
  |  Branch (117:10): [True: 6.17k, False: 4.72k]
  |  Branch (117:36): [True: 6.11k, False: 55]
  ------------------
  118|  6.11k|      const auto ext_type = static_cast<Extension_Code>(reader.get_uint16_t());
  119|  6.11k|      const auto ext_length = reader.get_uint16_t();
  120|       |
  121|       |      // skip over all extensions, finding the PSK extension to be truncated
  122|  6.11k|      if(ext_type != Extension_Code::PresharedKey) {
  ------------------
  |  Branch (122:10): [True: 5.42k, False: 693]
  ------------------
  123|  5.42k|         reader.discard_next(ext_length);
  124|  5.42k|         continue;
  125|  5.42k|      }
  126|       |
  127|       |      // PSK identities list
  128|    693|      const auto identities_length = reader.get_uint16_t();
  129|    693|      reader.discard_next(identities_length);
  130|       |
  131|       |      // check that only the binders are left in the buffer...
  132|    693|      const auto binders_length = reader.peek_uint16_t();
  133|    693|      if(binders_length != reader.remaining_bytes() - 2 /* binders_length */) {
  ------------------
  |  Branch (133:10): [True: 22, False: 671]
  ------------------
  134|     22|         throw TLS_Exception(Alert::IllegalParameter,
  135|     22|                             "Failed to truncate Client Hello that doesn't end on the PSK binders list");
  136|     22|      }
  137|       |
  138|       |      // the reader now points to the truncation point
  139|    671|      break;
  140|    693|   }
  141|       |
  142|       |   // if no PSK extension was found, this will point to the end of the buffer
  143|  5.45k|   return reader.read_so_far();
  144|  5.47k|}
tls_transcript_hash_13.cpp:_ZN5Botan3TLS12_GLOBAL__N_115read_hash_stateERNSt3__110unique_ptrINS_12HashFunctionENS2_14default_deleteIS4_EEEE:
  146|  28.9k|std::vector<uint8_t> read_hash_state(std::unique_ptr<HashFunction>& hash) {
  147|       |   // Botan does not support finalizing a HashFunction without resetting
  148|       |   // the internal state of the hash. Hence we first copy the internal
  149|       |   // state and then finalize the transient HashFunction.
  150|  28.9k|   return hash->copy_state()->final_stdvec();
  151|  28.9k|}

_ZN5Botan3TLS10ExtensionsD2Ev:
  140|  29.7k|Extensions::~Extensions() = default;
_ZNK5Botan3TLS10Extensions3hasENS0_14Extension_CodeE:
  142|  57.0k|bool Extensions::has(Extension_Code type) const {
  143|  57.0k|   return m_extensions.contains(type);
  144|  57.0k|}
_ZNK5Botan3TLS10Extensions3getENS0_14Extension_CodeE:
  146|  31.8k|Extension* Extensions::get(Extension_Code type) const {
  147|  31.8k|   const auto i = m_extensions.find(type);
  148|       |
  149|  31.8k|   if(i == m_extensions.end()) {
  ------------------
  |  Branch (149:7): [True: 13.4k, False: 18.3k]
  ------------------
  150|  13.4k|      return nullptr;
  151|  18.3k|   } else {
  152|  18.3k|      return i->second.get();
  153|  18.3k|   }
  154|  31.8k|}
_ZN5Botan3TLS10Extensions3addENSt3__110unique_ptrINS0_9ExtensionENS2_14default_deleteIS4_EEEE:
  156|  27.9k|void Extensions::add(std::unique_ptr<Extension> extn) {
  157|  27.9k|   const auto type = extn->type();
  158|  27.9k|   if(has(type)) {
  ------------------
  |  Branch (158:7): [True: 0, False: 27.9k]
  ------------------
  159|      0|      throw Invalid_Argument("cannot add the same extension twice: " + std::to_string(static_cast<uint16_t>(type)));
  160|      0|   }
  161|       |
  162|  27.9k|   m_extension_codes.push_back(type);
  163|  27.9k|   m_extensions.emplace(type, std::move(extn));
  164|  27.9k|}
_ZN5Botan3TLS10Extensions11deserializeERNS0_15TLS_Data_ReaderENS0_15Connection_SideENS0_14Handshake_TypeE:
  166|  18.9k|void Extensions::deserialize(TLS_Data_Reader& reader, const Connection_Side from, const Handshake_Type message_type) {
  167|  18.9k|   if(reader.has_remaining()) {
  ------------------
  |  Branch (167:7): [True: 15.5k, False: 3.42k]
  ------------------
  168|  15.5k|      const uint16_t all_extn_size = reader.get_uint16_t();
  169|       |
  170|  15.5k|      if(reader.remaining_bytes() != all_extn_size) {
  ------------------
  |  Branch (170:10): [True: 40, False: 15.5k]
  ------------------
  171|     40|         throw Decoding_Error("Bad extension size");
  172|     40|      }
  173|       |
  174|  44.7k|      while(reader.has_remaining()) {
  ------------------
  |  Branch (174:13): [True: 29.2k, False: 15.5k]
  ------------------
  175|  29.2k|         const uint16_t extension_code = reader.get_uint16_t();
  176|  29.2k|         const uint16_t extension_size = reader.get_uint16_t();
  177|       |
  178|  29.2k|         const auto type = static_cast<Extension_Code>(extension_code);
  179|       |
  180|  29.2k|         if(this->has(type)) {
  ------------------
  |  Branch (180:13): [True: 3, False: 29.2k]
  ------------------
  181|      3|            throw TLS_Exception(TLS::Alert::DecodeError, "Peer sent duplicated extensions");
  182|      3|         }
  183|       |
  184|       |         // TODO offer a function on reader that returns a byte range as a reference
  185|       |         // to avoid this copy of the extension data
  186|  29.2k|         const std::vector<uint8_t> extn_data = reader.get_fixed<uint8_t>(extension_size);
  187|  29.2k|         m_raw_extension_data[type] = extn_data;
  188|  29.2k|         TLS_Data_Reader extn_reader("Extension", extn_data);
  189|  29.2k|         this->add(make_extension(extn_reader, type, from, message_type));
  190|  29.2k|         extn_reader.assert_done();
  191|  29.2k|      }
  192|  15.5k|   }
  193|  18.9k|}
_ZNK5Botan3TLS10Extensions19contains_other_thanERKNSt3__13setINS0_14Extension_CodeENS2_4lessIS4_EENS2_9allocatorIS4_EEEEb:
  196|  8.28k|                                     const bool allow_unknown_extensions) const {
  197|  8.28k|   const auto found = extension_types();
  198|       |
  199|  8.28k|   std::vector<Extension_Code> diff;
  200|  8.28k|   std::set_difference(
  201|  8.28k|      found.cbegin(), found.end(), allowed_extensions.cbegin(), allowed_extensions.cend(), std::back_inserter(diff));
  202|       |
  203|  8.28k|   if(allow_unknown_extensions) {
  ------------------
  |  Branch (203:7): [True: 7.75k, False: 528]
  ------------------
  204|       |      // Go through the found unexpected extensions whether any of those
  205|       |      // is known to this TLS implementation.
  206|  7.75k|      const auto itr = std::find_if(diff.cbegin(), diff.cend(), [this](const auto ext_type) {
  207|  7.75k|         const auto ext = get(ext_type);
  208|  7.75k|         return ext && ext->is_implemented();
  209|  7.75k|      });
  210|       |
  211|       |      // ... if yes, `contains_other_than` is true
  212|  7.75k|      return itr != diff.cend();
  213|  7.75k|   }
  214|       |
  215|    528|   return !diff.empty();
  216|  8.28k|}
_ZNK5Botan3TLS10Extensions15extension_typesEv:
  273|  8.28k|std::set<Extension_Code> Extensions::extension_types() const {
  274|  8.28k|   std::set<Extension_Code> offers;
  275|  18.5k|   for(const auto& [extn_type, extn] : m_extensions) {
  ------------------
  |  Branch (275:38): [True: 18.5k, False: 8.28k]
  ------------------
  276|       |      // Consistent with serialize(): empty extensions are not placed on
  277|       |      // the wire so they must not appear in the "offered" set either.
  278|  18.5k|      if(!extn->empty()) {
  ------------------
  |  Branch (278:10): [True: 18.3k, False: 206]
  ------------------
  279|  18.3k|         offers.insert(extn_type);
  280|  18.3k|      }
  281|  18.5k|   }
  282|  8.28k|   return offers;
  283|  8.28k|}
_ZN5Botan3TLS17Unknown_ExtensionC2ENS0_14Extension_CodeERNS0_15TLS_Data_ReaderEt:
  313|  12.5k|      m_type(type), m_value(reader.get_fixed<uint8_t>(extension_size)) {}
_ZN5Botan3TLS21Server_Name_IndicatorC2ERNS0_15TLS_Data_ReaderEtNS0_15Connection_SideE:
  319|    941|Server_Name_Indicator::Server_Name_Indicator(TLS_Data_Reader& reader, uint16_t extension_size, Connection_Side from) {
  320|       |   /*
  321|       |   RFC 6066 Section 3
  322|       |
  323|       |      A server that receives a client hello containing the "server_name"
  324|       |      extension MAY use the information contained in the extension to guide
  325|       |      its selection of an appropriate certificate to return to the client,
  326|       |      and/or other aspects of security policy.  In this event, the server
  327|       |      SHALL include an extension of type "server_name" in the (extended)
  328|       |      server hello.  The "extension_data" field of this extension SHALL be
  329|       |      empty.
  330|       |   */
  331|    941|   if(from == Connection_Side::Server) {
  ------------------
  |  Branch (331:7): [True: 731, False: 210]
  ------------------
  332|    731|      if(extension_size != 0) {
  ------------------
  |  Branch (332:10): [True: 5, False: 726]
  ------------------
  333|      5|         throw TLS_Exception(Alert::IllegalParameter, "Server sent non-empty SNI extension");
  334|      5|      }
  335|    731|   } else {
  336|       |      // Clients are required to send at least one name in the SNI
  337|    210|      if(extension_size == 0) {
  ------------------
  |  Branch (337:10): [True: 1, False: 209]
  ------------------
  338|      1|         throw TLS_Exception(Alert::IllegalParameter, "Client sent empty SNI extension");
  339|      1|      }
  340|       |
  341|    209|      const uint16_t name_bytes = reader.get_uint16_t();
  342|       |
  343|       |      // RFC 6066 3: a ServerName carrying a host_name (the only NameType
  344|       |      // currently defined and the only one this implementation acts on)
  345|       |      // requires at least 1 byte name_type + 2 byte length + 1 byte HostName.
  346|    209|      if(name_bytes + 2 != extension_size || name_bytes < 4) {
  ------------------
  |  Branch (346:10): [True: 28, False: 181]
  |  Branch (346:46): [True: 2, False: 179]
  ------------------
  347|     28|         throw Decoding_Error("Bad encoding of SNI extension");
  348|     28|      }
  349|       |
  350|    181|      BOTAN_ASSERT_NOMSG(reader.remaining_bytes() == name_bytes);
  ------------------
  |  |   84|    181|   do {                                                                     \
  |  |   85|    181|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|    181|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 181]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|    181|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 181]
  |  |  ------------------
  ------------------
  351|       |
  352|    640|      while(reader.has_remaining()) {
  ------------------
  |  Branch (352:13): [True: 469, False: 171]
  ------------------
  353|    469|         const uint8_t name_type = reader.get_byte();
  354|       |
  355|    469|         if(name_type == 0) {
  ------------------
  |  Branch (355:13): [True: 172, False: 297]
  ------------------
  356|       |            /*
  357|       |            RFC 6066 Section 3
  358|       |               The ServerNameList MUST NOT contain more than one name of the same name_type.
  359|       |            */
  360|    172|            if(!m_sni_host_name.empty()) {
  ------------------
  |  Branch (360:16): [True: 10, False: 162]
  ------------------
  361|     10|               throw Decoding_Error("TLS ServerNameIndicator contains more than one host_name");
  362|     10|            }
  363|    162|            m_sni_host_name = reader.get_string(2, 1, 65535);
  364|    297|         } else {
  365|       |            /*
  366|       |            Unknown name type - skip its length-prefixed value and continue
  367|       |
  368|       |            RFC 6066 Section 3
  369|       |               For backward compatibility, all future data structures associated
  370|       |               with new NameTypes MUST begin with a 16-bit length field.
  371|       |            */
  372|    297|            const uint16_t unknown_name_len = reader.get_uint16_t();
  373|    297|            reader.discard_next(unknown_name_len);
  374|    297|         }
  375|    469|      }
  376|    181|   }
  377|    941|}
_ZN5Botan3TLS39Application_Layer_Protocol_NotificationC2ERNS0_15TLS_Data_ReaderEtNS0_15Connection_SideE:
  447|    708|                                                                                 Connection_Side from) {
  448|    708|   if(extension_size < 2) {
  ------------------
  |  Branch (448:7): [True: 4, False: 704]
  ------------------
  449|      4|      throw Decoding_Error("ALPN extension cannot be empty");
  450|      4|   }
  451|       |
  452|    704|   const uint16_t name_bytes = reader.get_uint16_t();
  453|       |
  454|    704|   size_t bytes_remaining = extension_size - 2;
  455|       |
  456|    704|   if(name_bytes != bytes_remaining) {
  ------------------
  |  Branch (456:7): [True: 29, False: 675]
  ------------------
  457|     29|      throw Decoding_Error("Bad encoding of ALPN extension, bad length field");
  458|     29|   }
  459|       |
  460|       |   // RFC 7301 3.1: ProtocolName protocol_name_list<2..2^16-1>
  461|    675|   if(name_bytes == 0) {
  ------------------
  |  Branch (461:7): [True: 1, False: 674]
  ------------------
  462|      1|      throw Decoding_Error("Empty ALPN protocol_name_list not allowed");
  463|      1|   }
  464|       |
  465|  3.09k|   while(bytes_remaining > 0) {
  ------------------
  |  Branch (465:10): [True: 2.44k, False: 652]
  ------------------
  466|  2.44k|      const std::string p = reader.get_string(1, 0, 255);
  467|       |
  468|  2.44k|      if(bytes_remaining < p.size() + 1) {
  ------------------
  |  Branch (468:10): [True: 0, False: 2.44k]
  ------------------
  469|      0|         throw Decoding_Error("Bad encoding of ALPN, length field too long");
  470|      0|      }
  471|       |
  472|  2.44k|      if(p.empty()) {
  ------------------
  |  Branch (472:10): [True: 22, False: 2.41k]
  ------------------
  473|     22|         throw Decoding_Error("Empty ALPN protocol not allowed");
  474|     22|      }
  475|       |
  476|  2.41k|      bytes_remaining -= (p.size() + 1);
  477|       |
  478|  2.41k|      m_protocols.push_back(p);
  479|  2.41k|   }
  480|       |
  481|       |   // RFC 7301 3.1
  482|       |   //    The "extension_data" field of the [...] extension is structured the
  483|       |   //    same as described above for the client "extension_data", except that
  484|       |   //    the "ProtocolNameList" MUST contain exactly one "ProtocolName".
  485|    652|   if(from == Connection_Side::Server && m_protocols.size() != 1) {
  ------------------
  |  Branch (485:7): [True: 497, False: 155]
  |  Branch (485:42): [True: 17, False: 480]
  ------------------
  486|     17|      throw TLS_Exception(
  487|     17|         Alert::DecodeError,
  488|     17|         "Server sent " + std::to_string(m_protocols.size()) + " protocols in ALPN extension response");
  489|     17|   }
  490|    652|}
_ZN5Botan3TLS21Certificate_Type_BaseC2ERNS0_15TLS_Data_ReaderEtNS0_15Connection_SideE:
  553|  1.25k|      m_from(from) {
  554|  1.25k|   if(extension_size == 0) {
  ------------------
  |  Branch (554:7): [True: 7, False: 1.24k]
  ------------------
  555|      7|      throw Decoding_Error("Certificate type extension cannot be empty");
  556|      7|   }
  557|       |
  558|  1.24k|   if(from == Connection_Side::Client) {
  ------------------
  |  Branch (558:7): [True: 289, False: 960]
  ------------------
  559|    289|      const auto type_bytes = reader.get_tls_length_value(1);
  560|    289|      if(static_cast<size_t>(extension_size) != type_bytes.size() + 1) {
  ------------------
  |  Branch (560:10): [True: 2, False: 287]
  ------------------
  561|      2|         throw Decoding_Error("certificate type extension had inconsistent length");
  562|      2|      }
  563|       |      // RFC 7250 4: {client,server}_certificate_types<1..2^8-1> so must be non-empty
  564|    287|      if(type_bytes.empty()) {
  ------------------
  |  Branch (564:10): [True: 1, False: 286]
  ------------------
  565|      1|         throw Decoding_Error("Certificate type extension contains no types");
  566|      1|      }
  567|    286|      std::transform(
  568|    286|         type_bytes.begin(), type_bytes.end(), std::back_inserter(m_certificate_types), [](const auto type_byte) {
  569|    286|            return static_cast<Certificate_Type>(type_byte);
  570|    286|         });
  571|    960|   } else {
  572|       |      // RFC 7250 4.2
  573|       |      //    Note that only a single value is permitted in the
  574|       |      //    server_certificate_type extension when carried in the server hello.
  575|    960|      if(extension_size != 1) {
  ------------------
  |  Branch (575:10): [True: 9, False: 951]
  ------------------
  576|      9|         throw Decoding_Error("Server's certificate type extension must be of length 1");
  577|      9|      }
  578|    951|      const auto type_byte = reader.get_byte();
  579|    951|      m_certificate_types.push_back(static_cast<Certificate_Type>(type_byte));
  580|    951|   }
  581|  1.24k|}
_ZNK5Botan3TLS16Supported_Groups6groupsEv:
  622|    233|const std::vector<Group_Params>& Supported_Groups::groups() const {
  623|    233|   return m_groups;
  624|    233|}
_ZN5Botan3TLS16Supported_GroupsC2ERNS0_15TLS_Data_ReaderEt:
  666|  1.83k|Supported_Groups::Supported_Groups(TLS_Data_Reader& reader, uint16_t extension_size) {
  667|  1.83k|   const uint16_t len = reader.get_uint16_t();
  668|       |
  669|  1.83k|   if(len + 2 != extension_size) {
  ------------------
  |  Branch (669:7): [True: 21, False: 1.81k]
  ------------------
  670|     21|      throw Decoding_Error("Inconsistent length field in supported groups list");
  671|     21|   }
  672|       |
  673|       |   // RFC 8446 4.2.7: NamedGroup named_group_list<2..2^16-1>;
  674|  1.81k|   if(len == 0) {
  ------------------
  |  Branch (674:7): [True: 1, False: 1.81k]
  ------------------
  675|      1|      throw Decoding_Error("Empty supported groups list");
  676|      1|   }
  677|       |
  678|  1.81k|   if(len % 2 == 1) {
  ------------------
  |  Branch (678:7): [True: 1, False: 1.81k]
  ------------------
  679|      1|      throw Decoding_Error("Supported groups list of strange size");
  680|      1|   }
  681|       |
  682|  1.81k|   const size_t elems = len / 2;
  683|       |
  684|  1.81k|   std::unordered_set<uint16_t> seen;
  685|  19.8k|   for(size_t i = 0; i != elems; ++i) {
  ------------------
  |  Branch (685:22): [True: 18.0k, False: 1.81k]
  ------------------
  686|  18.0k|      const auto group = static_cast<Group_Params>(reader.get_uint16_t());
  687|       |      // Note: RFC 8446 does not explicitly enforce that groups must be unique.
  688|  18.0k|      if(seen.insert(group.wire_code()).second) {
  ------------------
  |  Branch (688:10): [True: 14.9k, False: 3.06k]
  ------------------
  689|  14.9k|         m_groups.push_back(group);
  690|  14.9k|      }
  691|  18.0k|   }
  692|  1.81k|}
_ZN5Botan3TLS20Signature_AlgorithmsC2ERNS0_15TLS_Data_ReaderEt:
  738|  1.73k|      m_schemes(parse_signature_algorithms(reader, extension_size)) {}
_ZN5Botan3TLS25Signature_Algorithms_CertC2ERNS0_15TLS_Data_ReaderEt:
  745|    313|      m_schemes(parse_signature_algorithms(reader, extension_size)) {}
_ZN5Botan3TLS24SRTP_Protection_ProfilesC2ERNS0_15TLS_Data_ReaderEt:
  747|    314|SRTP_Protection_Profiles::SRTP_Protection_Profiles(TLS_Data_Reader& reader, uint16_t extension_size) {
  748|       |   // RFC 5764 4.1.1: UseSRTPData consists of
  749|       |   //    SRTPProtectionProfile SRTPProtectionProfiles<2..2^16-1>;
  750|       |   //    opaque srtp_mki<0..255>;
  751|       |   // for a wire size of 2 (profiles len) + 2*N + 1 (mki len) + mki_bytes,
  752|       |   // with N >= 1.
  753|    314|   if(extension_size < 5) {
  ------------------
  |  Branch (753:7): [True: 3, False: 311]
  ------------------
  754|      3|      throw Decoding_Error("Truncated SRTP protection extension");
  755|      3|   }
  756|    311|   const size_t max_profile_pairs = (static_cast<size_t>(extension_size) - 3) / 2;
  757|    311|   m_pp = reader.get_range<uint16_t>(2, 1, max_profile_pairs);
  758|    311|   const std::vector<uint8_t> mki = reader.get_range<uint8_t>(1, 0, 255);
  759|       |
  760|    311|   if(m_pp.size() * 2 + mki.size() + 3 != extension_size) {
  ------------------
  |  Branch (760:7): [True: 17, False: 294]
  ------------------
  761|     17|      throw Decoding_Error("Bad encoding for SRTP protection extension");
  762|     17|   }
  763|       |
  764|    294|   if(!mki.empty()) {
  ------------------
  |  Branch (764:7): [True: 5, False: 289]
  ------------------
  765|      5|      throw Decoding_Error("Unhandled non-empty MKI for SRTP protection extension");
  766|      5|   }
  767|    294|}
_ZN5Botan3TLS18Supported_VersionsC2ERNS0_15TLS_Data_ReaderEtNS0_15Connection_SideE:
  842|  1.15k|Supported_Versions::Supported_Versions(TLS_Data_Reader& reader, uint16_t extension_size, Connection_Side from) {
  843|  1.15k|   if(from == Connection_Side::Server) {
  ------------------
  |  Branch (843:7): [True: 576, False: 576]
  ------------------
  844|    576|      if(extension_size != 2) {
  ------------------
  |  Branch (844:10): [True: 2, False: 574]
  ------------------
  845|      2|         throw Decoding_Error("Server sent invalid supported_versions extension");
  846|      2|      }
  847|    574|      m_versions.push_back(Protocol_Version(reader.get_uint16_t()));
  848|    576|   } else {
  849|    576|      auto versions = reader.get_range<uint16_t>(1, 1, 127);
  850|       |
  851|  2.63k|      for(auto v : versions) {
  ------------------
  |  Branch (851:18): [True: 2.63k, False: 576]
  ------------------
  852|  2.63k|         m_versions.push_back(Protocol_Version(v));
  853|  2.63k|      }
  854|       |
  855|    576|      if(extension_size != 1 + 2 * versions.size()) {
  ------------------
  |  Branch (855:10): [True: 9, False: 567]
  ------------------
  856|      9|         throw Decoding_Error("Client sent invalid supported_versions extension");
  857|      9|      }
  858|    576|   }
  859|  1.15k|}
_ZNK5Botan3TLS18Supported_Versions8supportsENS0_16Protocol_VersionE:
  861|    564|bool Supported_Versions::supports(Protocol_Version version) const {
  862|  1.60k|   for(auto v : m_versions) {
  ------------------
  |  Branch (862:15): [True: 1.60k, False: 198]
  ------------------
  863|  1.60k|      if(version == v) {
  ------------------
  |  Branch (863:10): [True: 366, False: 1.23k]
  ------------------
  864|    366|         return true;
  865|    366|      }
  866|  1.60k|   }
  867|    198|   return false;
  868|    564|}
_ZN5Botan3TLS17Record_Size_LimitC2ERNS0_15TLS_Data_ReaderEtNS0_15Connection_SideE:
  876|    610|Record_Size_Limit::Record_Size_Limit(TLS_Data_Reader& reader, uint16_t extension_size, Connection_Side from) {
  877|    610|   if(extension_size != 2) {
  ------------------
  |  Branch (877:7): [True: 11, False: 599]
  ------------------
  878|     11|      throw TLS_Exception(Alert::DecodeError, "invalid record_size_limit extension");
  879|     11|   }
  880|       |
  881|    599|   m_limit = reader.get_uint16_t();
  882|       |
  883|       |   // RFC 8449 4.
  884|       |   //    This value is the length of the plaintext of a protected record.
  885|       |   //    The value includes the content type and padding added in TLS 1.3 (that
  886|       |   //    is, the complete length of TLSInnerPlaintext).
  887|       |   //
  888|       |   //    A server MUST NOT enforce this restriction; a client might advertise
  889|       |   //    a higher limit that is enabled by an extension or version the server
  890|       |   //    does not understand. A client MAY abort the handshake with an
  891|       |   //    "illegal_parameter" alert.
  892|       |   //
  893|       |   // Note: We are currently supporting this extension in TLS 1.3 only, hence
  894|       |   //       we check for the TLS 1.3 limit. The TLS 1.2 limit would not include
  895|       |   //       the "content type byte" and hence be one byte less!
  896|    599|   if(m_limit > MAX_PLAINTEXT_SIZE + 1 /* encrypted content type byte */ && from == Connection_Side::Server) {
  ------------------
  |  Branch (896:7): [True: 74, False: 525]
  |  Branch (896:77): [True: 2, False: 72]
  ------------------
  897|      2|      throw TLS_Exception(Alert::IllegalParameter,
  898|      2|                          "Server requested a record size limit larger than the protocol's maximum");
  899|      2|   }
  900|       |
  901|       |   // RFC 8449 4.
  902|       |   //    Endpoints MUST NOT send a "record_size_limit" extension with a value
  903|       |   //    smaller than 64.  An endpoint MUST treat receipt of a smaller value
  904|       |   //    as a fatal error and generate an "illegal_parameter" alert.
  905|    597|   if(m_limit < 64) {
  ------------------
  |  Branch (905:7): [True: 5, False: 592]
  ------------------
  906|      5|      throw TLS_Exception(Alert::IllegalParameter, "Received a record size limit smaller than 64 bytes");
  907|      5|   }
  908|    597|}
tls_extensions.cpp:_ZN5Botan3TLS12_GLOBAL__N_114make_extensionERNS0_15TLS_Data_ReaderENS0_14Extension_CodeENS0_15Connection_SideENS0_14Handshake_TypeE:
   41|  29.1k|                                          const Handshake_Type message_type) {
   42|       |   // This cast is safe because we read exactly a 16 bit length field for
   43|       |   // the extension in Extensions::deserialize
   44|  29.1k|   const uint16_t size = static_cast<uint16_t>(reader.remaining_bytes());
   45|  29.1k|   switch(code) {
  ------------------
  |  Branch (45:11): [True: 16.7k, False: 12.3k]
  ------------------
   46|    941|      case Extension_Code::ServerNameIndication:
  ------------------
  |  Branch (46:7): [True: 941, False: 28.1k]
  ------------------
   47|    941|         return std::make_unique<Server_Name_Indicator>(reader, size, from);
   48|       |
   49|  1.83k|      case Extension_Code::SupportedGroups:
  ------------------
  |  Branch (49:7): [True: 1.83k, False: 27.2k]
  ------------------
   50|  1.83k|         return std::make_unique<Supported_Groups>(reader, size);
   51|       |
   52|  1.40k|      case Extension_Code::CertificateStatusRequest:
  ------------------
  |  Branch (52:7): [True: 1.40k, False: 27.7k]
  ------------------
   53|  1.40k|         return std::make_unique<Certificate_Status_Request>(reader, size, message_type, from);
   54|       |
   55|  1.73k|      case Extension_Code::SignatureAlgorithms:
  ------------------
  |  Branch (55:7): [True: 1.73k, False: 27.3k]
  ------------------
   56|  1.73k|         return std::make_unique<Signature_Algorithms>(reader, size);
   57|       |
   58|    313|      case Extension_Code::CertSignatureAlgorithms:
  ------------------
  |  Branch (58:7): [True: 313, False: 28.8k]
  ------------------
   59|    313|         return std::make_unique<Signature_Algorithms_Cert>(reader, size);
   60|       |
   61|    314|      case Extension_Code::UseSrtp:
  ------------------
  |  Branch (61:7): [True: 314, False: 28.8k]
  ------------------
   62|    314|         return std::make_unique<SRTP_Protection_Profiles>(reader, size);
   63|       |
   64|    708|      case Extension_Code::ApplicationLayerProtocolNegotiation:
  ------------------
  |  Branch (64:7): [True: 708, False: 28.4k]
  ------------------
   65|    708|         return std::make_unique<Application_Layer_Protocol_Notification>(reader, size, from);
   66|       |
   67|    573|      case Extension_Code::ClientCertificateType:
  ------------------
  |  Branch (67:7): [True: 573, False: 28.5k]
  ------------------
   68|    573|         return std::make_unique<Client_Certificate_Type>(reader, size, from);
   69|       |
   70|    683|      case Extension_Code::ServerCertificateType:
  ------------------
  |  Branch (70:7): [True: 683, False: 28.4k]
  ------------------
   71|    683|         return std::make_unique<Server_Certificate_Type>(reader, size, from);
   72|       |
   73|    610|      case Extension_Code::RecordSizeLimit:
  ------------------
  |  Branch (73:7): [True: 610, False: 28.5k]
  ------------------
   74|    610|         return std::make_unique<Record_Size_Limit>(reader, size, from);
   75|       |
   76|  1.15k|      case Extension_Code::SupportedVersions:
  ------------------
  |  Branch (76:7): [True: 1.15k, False: 27.9k]
  ------------------
   77|  1.15k|         return std::make_unique<Supported_Versions>(reader, size, from);
   78|       |
   79|    140|      case Extension_Code::Padding:
  ------------------
  |  Branch (79:7): [True: 140, False: 28.9k]
  ------------------
   80|    140|         break;  // RFC 7685, recognized but not implemented; falls through to Unknown_Extension
   81|       |
   82|      0|#if defined(BOTAN_HAS_TLS_12)
   83|    313|      case Extension_Code::EcPointFormats:
  ------------------
  |  Branch (83:7): [True: 313, False: 28.8k]
  ------------------
   84|    313|         return std::make_unique<Supported_Point_Formats>(reader, size);
   85|       |
   86|    324|      case Extension_Code::SafeRenegotiation:
  ------------------
  |  Branch (86:7): [True: 324, False: 28.7k]
  ------------------
   87|    324|         return std::make_unique<Renegotiation_Extension>(reader, size);
   88|       |
   89|     96|      case Extension_Code::ExtendedMasterSecret:
  ------------------
  |  Branch (89:7): [True: 96, False: 29.0k]
  ------------------
   90|     96|         return std::make_unique<Extended_Master_Secret>(reader, size);
   91|       |
   92|    300|      case Extension_Code::EncryptThenMac:
  ------------------
  |  Branch (92:7): [True: 300, False: 28.8k]
  ------------------
   93|    300|         return std::make_unique<Encrypt_then_MAC>(reader, size);
   94|       |
   95|    452|      case Extension_Code::SessionTicket:
  ------------------
  |  Branch (95:7): [True: 452, False: 28.6k]
  ------------------
   96|    452|         return std::make_unique<Session_Ticket_Extension>(reader, size, from);
   97|       |#else
   98|       |      case Extension_Code::EcPointFormats:
   99|       |      case Extension_Code::SafeRenegotiation:
  100|       |      case Extension_Code::ExtendedMasterSecret:
  101|       |      case Extension_Code::EncryptThenMac:
  102|       |      case Extension_Code::SessionTicket:
  103|       |         break;  // considered as 'unknown extension'
  104|       |#endif
  105|       |
  106|      0|#if defined(BOTAN_HAS_TLS_13)
  107|  1.28k|      case Extension_Code::PresharedKey:
  ------------------
  |  Branch (107:7): [True: 1.28k, False: 27.8k]
  ------------------
  108|  1.28k|         return std::make_unique<PSK>(reader, size, message_type);
  109|       |
  110|    285|      case Extension_Code::EarlyData:
  ------------------
  |  Branch (110:7): [True: 285, False: 28.8k]
  ------------------
  111|    285|         return std::make_unique<EarlyDataIndication>(reader, size, message_type);
  112|       |
  113|    232|      case Extension_Code::Cookie:
  ------------------
  |  Branch (113:7): [True: 232, False: 28.8k]
  ------------------
  114|    232|         return std::make_unique<Cookie>(reader, size);
  115|       |
  116|    700|      case Extension_Code::PskKeyExchangeModes:
  ------------------
  |  Branch (116:7): [True: 700, False: 28.4k]
  ------------------
  117|    700|         return std::make_unique<PSK_Key_Exchange_Modes>(reader, size);
  118|       |
  119|    819|      case Extension_Code::CertificateAuthorities:
  ------------------
  |  Branch (119:7): [True: 819, False: 28.2k]
  ------------------
  120|    819|         return std::make_unique<Certificate_Authorities>(reader, size);
  121|       |
  122|  1.50k|      case Extension_Code::KeyShare:
  ------------------
  |  Branch (122:7): [True: 1.50k, False: 27.6k]
  ------------------
  123|  1.50k|         return std::make_unique<Key_Share>(reader, size, message_type);
  124|       |#else
  125|       |      case Extension_Code::PresharedKey:
  126|       |      case Extension_Code::EarlyData:
  127|       |      case Extension_Code::Cookie:
  128|       |      case Extension_Code::PskKeyExchangeModes:
  129|       |      case Extension_Code::CertificateAuthorities:
  130|       |      case Extension_Code::KeyShare:
  131|       |         break;  // considered as 'unknown extension'
  132|       |#endif
  133|  29.1k|   }
  134|       |
  135|  12.5k|   return std::make_unique<Unknown_Extension>(code, reader, size);
  136|  29.1k|}
tls_extensions.cpp:_ZZNK5Botan3TLS10Extensions19contains_other_thanERKNSt3__13setINS0_14Extension_CodeENS2_4lessIS4_EENS2_9allocatorIS4_EEEEbENK3$_0clIS4_EEDaT_:
  206|  10.8k|      const auto itr = std::find_if(diff.cbegin(), diff.cend(), [this](const auto ext_type) {
  207|  10.8k|         const auto ext = get(ext_type);
  208|  10.8k|         return ext && ext->is_implemented();
  ------------------
  |  Branch (208:17): [True: 10.8k, False: 0]
  |  Branch (208:24): [True: 111, False: 10.7k]
  ------------------
  209|  10.8k|      });
tls_extensions.cpp:_ZZN5Botan3TLS21Certificate_Type_BaseC1ERNS0_15TLS_Data_ReaderEtNS0_15Connection_SideEENK3$_0clIhEEDaT_:
  568|  2.12k|         type_bytes.begin(), type_bytes.end(), std::back_inserter(m_certificate_types), [](const auto type_byte) {
  569|  2.12k|            return static_cast<Certificate_Type>(type_byte);
  570|  2.12k|         });
tls_extensions.cpp:_ZN5Botan3TLS12_GLOBAL__N_126parse_signature_algorithmsERNS0_15TLS_Data_ReaderEt:
  714|  2.04k|std::vector<Signature_Scheme> parse_signature_algorithms(TLS_Data_Reader& reader, uint16_t extension_size) {
  715|  2.04k|   uint16_t len = reader.get_uint16_t();
  716|       |
  717|  2.04k|   if(len + 2 != extension_size || len % 2 == 1 || len == 0) {
  ------------------
  |  Branch (717:7): [True: 30, False: 2.01k]
  |  Branch (717:36): [True: 1, False: 2.01k]
  |  Branch (717:52): [True: 1, False: 2.01k]
  ------------------
  718|     24|      throw Decoding_Error("Bad encoding on signature algorithms extension");
  719|     24|   }
  720|       |
  721|  2.02k|   std::vector<Signature_Scheme> schemes;
  722|  2.02k|   schemes.reserve(len / 2);
  723|  4.87k|   while(len > 0) {
  ------------------
  |  Branch (723:10): [True: 2.85k, False: 2.02k]
  ------------------
  724|  2.85k|      schemes.emplace_back(reader.get_uint16_t());
  725|  2.85k|      len -= 2;
  726|  2.85k|   }
  727|       |
  728|  2.02k|   return schemes;
  729|  2.04k|}

_ZN5Botan3TLS26Certificate_Status_RequestC2ERNS0_15TLS_Data_ReaderEtNS0_14Handshake_TypeENS0_15Connection_SideE:
  104|  1.40k|                                                       Connection_Side from) {
  105|       |   // This parser needs to take TLS 1.2 and TLS 1.3 into account. The
  106|       |   // extension's content and structure is dependent on the context it
  107|       |   // was sent in (i.e. the enclosing handshake message). Below is a list
  108|       |   // of handshake messages this can appear in.
  109|       |   //
  110|       |   // TLS 1.2
  111|       |   //  * Client Hello
  112|       |   //  * Server Hello
  113|       |   //
  114|       |   // TLS 1.3
  115|       |   //  * Client Hello
  116|       |   //  * Certificate Request
  117|       |   //  * Certificate (Entry)
  118|       |
  119|       |   // RFC 6066 8.
  120|       |   //    In order to indicate their desire to receive certificate status
  121|       |   //    information, clients MAY include an extension of type "status_request"
  122|       |   //    in the (extended) client hello.
  123|  1.40k|   if(message_type == Handshake_Type::ClientHello) {
  ------------------
  |  Branch (123:7): [True: 697, False: 712]
  ------------------
  124|    697|      m_impl = std::make_unique<Certificate_Status_Request_Internal>(
  125|    697|         RFC6066_Certificate_Status_Request(reader, extension_size));
  126|    697|   }
  127|       |
  128|       |   // RFC 6066 8.
  129|       |   //    If a server returns a "CertificateStatus" message, then the server MUST
  130|       |   //    have included an extension of type "status_request" with empty
  131|       |   //    "extension_data" in the extended server hello.
  132|       |   //
  133|       |   // RFC 8446 4.4.2.1
  134|       |   //    A server MAY request that a client present an OCSP response with its
  135|       |   //    certificate by sending an empty "status_request" extension in its
  136|       |   //    CertificateRequest message.
  137|    712|   else if(message_type == Handshake_Type::ServerHello || message_type == Handshake_Type::CertificateRequest) {
  ------------------
  |  Branch (137:12): [True: 304, False: 408]
  |  Branch (137:59): [True: 405, False: 3]
  ------------------
  138|    709|      m_impl = std::make_unique<Certificate_Status_Request_Internal>(
  139|    709|         RFC6066_Empty_Certificate_Status_Request(extension_size));
  140|    709|   }
  141|       |
  142|       |   // RFC 8446 4.4.2.1
  143|       |   //    In TLS 1.3, the server's OCSP information is carried in an extension
  144|       |   //    in the CertificateEntry [in a Certificate handshake message] [...].
  145|       |   //    Specifically, the body of the "status_request" extension from the
  146|       |   //    server MUST be a CertificateStatus structure as defined in [RFC6066]
  147|       |   //    [...].
  148|       |   //
  149|       |   // RFC 8446 4.4.2.1
  150|       |   //    If the client opts to send an OCSP response, the body of its
  151|       |   //    "status_request" extension MUST be a CertificateStatus structure as
  152|       |   //    defined in [RFC6066].
  153|      3|   else if(message_type == Handshake_Type::Certificate) {
  ------------------
  |  Branch (153:12): [True: 0, False: 3]
  ------------------
  154|      0|      m_impl = std::make_unique<Certificate_Status_Request_Internal>(
  155|      0|         Certificate_Status(reader.get_fixed<uint8_t>(extension_size), from));
  156|      0|   }
  157|       |
  158|       |   // all other contexts are not allowed for this extension
  159|      3|   else {
  160|      3|      throw TLS_Exception(Alert::UnsupportedExtension,
  161|      3|                          "Server sent a Certificate_Status_Request extension in an unsupported context");
  162|      3|   }
  163|  1.40k|}
_ZN5Botan3TLS26Certificate_Status_RequestD2Ev:
  176|  1.36k|Certificate_Status_Request::~Certificate_Status_Request() = default;
tls_extensions_cert_status_req.cpp:_ZN5Botan3TLS12_GLOBAL__N_134RFC6066_Certificate_Status_RequestC2ERNS0_15TLS_Data_ReaderEt:
   38|    697|      RFC6066_Certificate_Status_Request(TLS_Data_Reader& reader, uint16_t extension_size) {
   39|    697|         if(extension_size == 0) {
  ------------------
  |  Branch (39:13): [True: 1, False: 696]
  ------------------
   40|      1|            throw Decoding_Error("Received an unexpectedly empty Certificate_Status_Request");
   41|      1|         }
   42|       |
   43|    696|         const uint8_t type = reader.get_byte();
   44|    696|         if(type == 1 /* ocsp */) {
  ------------------
  |  Branch (44:13): [True: 208, False: 488]
  ------------------
   45|       |            // RFC 6066 Section 8: OCSP CertificateStatusRequest is
   46|       |            //    ResponderID responder_id_list<0..2^16-1>;
   47|       |            //    Extensions  request_extensions;
   48|       |            //
   49|       |            // for a total wire size of 1 (status_type) + 2 (resp_id_list len)
   50|       |            //   + len_resp_id_list + 2 (request_ext len) + len_requ_ext.
   51|    208|            if(extension_size < 5) {
  ------------------
  |  Branch (51:16): [True: 2, False: 206]
  ------------------
   52|      2|               throw Decoding_Error("Truncated OCSP CertificateStatusRequest");
   53|      2|            }
   54|    206|            const size_t len_resp_id_list = reader.get_uint16_t();
   55|    206|            if(len_resp_id_list > static_cast<size_t>(extension_size) - 5) {
  ------------------
  |  Branch (55:16): [True: 1, False: 205]
  ------------------
   56|      1|               throw Decoding_Error("Inconsistent length in OCSP CertificateStatusRequest");
   57|      1|            }
   58|    205|            ocsp_names = reader.get_fixed<uint8_t>(len_resp_id_list);
   59|    205|            const size_t len_requ_ext = reader.get_uint16_t();
   60|    205|            if(len_resp_id_list + len_requ_ext + 5 != extension_size) {
  ------------------
  |  Branch (60:16): [True: 28, False: 177]
  ------------------
   61|     28|               throw Decoding_Error("Inconsistent length in OCSP CertificateStatusRequest");
   62|     28|            }
   63|    177|            extension_bytes = reader.get_fixed<uint8_t>(len_requ_ext);
   64|    488|         } else {
   65|       |            // RFC 6066 does not specify anything but 'ocsp' and we
   66|       |            // don't support anything else either.
   67|    488|            reader.discard_next(extension_size - 1);
   68|    488|         }
   69|    696|      }
tls_extensions_cert_status_req.cpp:_ZN5Botan3TLS12_GLOBAL__N_140RFC6066_Empty_Certificate_Status_RequestC2Et:
   24|    709|      explicit RFC6066_Empty_Certificate_Status_Request(uint16_t extension_size) {
   25|    709|         if(extension_size != 0) {
  ------------------
  |  Branch (25:13): [True: 5, False: 704]
  ------------------
   26|      5|            throw Decoding_Error("Received an unexpectedly non-empty Certificate_Status_Request");
   27|      5|         }
   28|    709|      }
tls_extensions_cert_status_req.cpp:_ZN5Botan3TLS35Certificate_Status_Request_InternalC2ENSt3__17variantIJNS0_12_GLOBAL__N_140RFC6066_Empty_Certificate_Status_RequestENS4_34RFC6066_Certificate_Status_RequestENS0_18Certificate_StatusEEEE:
   96|  1.36k|      explicit Certificate_Status_Request_Internal(Contents c) : content(std::move(c)) {}

_ZN5Botan3TLS24handshake_type_to_stringENS0_14Handshake_TypeE:
   15|      4|const char* handshake_type_to_string(Handshake_Type type) {
   16|      4|   switch(type) {
  ------------------
  |  Branch (16:11): [True: 4, False: 0]
  ------------------
   17|      0|      case Handshake_Type::HelloVerifyRequest:
  ------------------
  |  Branch (17:7): [True: 0, False: 4]
  ------------------
   18|      0|         return "hello_verify_request";
   19|       |
   20|      0|      case Handshake_Type::HelloRequest:
  ------------------
  |  Branch (20:7): [True: 0, False: 4]
  ------------------
   21|      0|         return "hello_request";
   22|       |
   23|      0|      case Handshake_Type::ClientHello:
  ------------------
  |  Branch (23:7): [True: 0, False: 4]
  ------------------
   24|      0|         return "client_hello";
   25|       |
   26|      0|      case Handshake_Type::ServerHello:
  ------------------
  |  Branch (26:7): [True: 0, False: 4]
  ------------------
   27|      0|         return "server_hello";
   28|       |
   29|      0|      case Handshake_Type::HelloRetryRequest:
  ------------------
  |  Branch (29:7): [True: 0, False: 4]
  ------------------
   30|      0|         return "hello_retry_request";
   31|       |
   32|      0|      case Handshake_Type::Certificate:
  ------------------
  |  Branch (32:7): [True: 0, False: 4]
  ------------------
   33|      0|         return "certificate";
   34|       |
   35|      0|      case Handshake_Type::CertificateUrl:
  ------------------
  |  Branch (35:7): [True: 0, False: 4]
  ------------------
   36|      0|         return "certificate_url";
   37|       |
   38|      0|      case Handshake_Type::CertificateStatus:
  ------------------
  |  Branch (38:7): [True: 0, False: 4]
  ------------------
   39|      0|         return "certificate_status";
   40|       |
   41|      0|      case Handshake_Type::ServerKeyExchange:
  ------------------
  |  Branch (41:7): [True: 0, False: 4]
  ------------------
   42|      0|         return "server_key_exchange";
   43|       |
   44|      2|      case Handshake_Type::CertificateRequest:
  ------------------
  |  Branch (44:7): [True: 2, False: 2]
  ------------------
   45|      2|         return "certificate_request";
   46|       |
   47|      0|      case Handshake_Type::ServerHelloDone:
  ------------------
  |  Branch (47:7): [True: 0, False: 4]
  ------------------
   48|      0|         return "server_hello_done";
   49|       |
   50|      0|      case Handshake_Type::CertificateVerify:
  ------------------
  |  Branch (50:7): [True: 0, False: 4]
  ------------------
   51|      0|         return "certificate_verify";
   52|       |
   53|      0|      case Handshake_Type::ClientKeyExchange:
  ------------------
  |  Branch (53:7): [True: 0, False: 4]
  ------------------
   54|      0|         return "client_key_exchange";
   55|       |
   56|      0|      case Handshake_Type::NewSessionTicket:
  ------------------
  |  Branch (56:7): [True: 0, False: 4]
  ------------------
   57|      0|         return "new_session_ticket";
   58|       |
   59|      0|      case Handshake_Type::HandshakeCCS:
  ------------------
  |  Branch (59:7): [True: 0, False: 4]
  ------------------
   60|      0|         return "change_cipher_spec";
   61|       |
   62|      0|      case Handshake_Type::Finished:
  ------------------
  |  Branch (62:7): [True: 0, False: 4]
  ------------------
   63|      0|         return "finished";
   64|       |
   65|      0|      case Handshake_Type::EndOfEarlyData:
  ------------------
  |  Branch (65:7): [True: 0, False: 4]
  ------------------
   66|      0|         return "end_of_early_data";
   67|       |
   68|      2|      case Handshake_Type::EncryptedExtensions:
  ------------------
  |  Branch (68:7): [True: 2, False: 2]
  ------------------
   69|      2|         return "encrypted_extensions";
   70|       |
   71|      0|      case Handshake_Type::KeyUpdate:
  ------------------
  |  Branch (71:7): [True: 0, False: 4]
  ------------------
   72|      0|         return "key_update";
   73|       |
   74|      0|      case Handshake_Type::None:
  ------------------
  |  Branch (74:7): [True: 0, False: 4]
  ------------------
   75|      0|         return "invalid";
   76|      4|   }
   77|       |
   78|      0|   throw TLS_Exception(Alert::UnexpectedMessage,
   79|      0|                       "Unknown TLS handshake message type " + std::to_string(static_cast<size_t>(type)));
   80|      4|}

_ZNK5Botan3TLS6Policy30maximum_handshake_message_sizeEv:
  491|  33.3k|size_t Policy::maximum_handshake_message_size() const {
  492|  33.3k|   return 65536;
  493|  33.3k|}
_ZNK5Botan3TLS6Policy30maximum_certificate_chain_sizeEv:
  495|  2.93k|size_t Policy::maximum_certificate_chain_size() const {
  496|  2.93k|   return 65536;
  497|  2.93k|}

_ZNK5Botan3TLS15TLS_Data_Reader15assert_at_leastEm:
   14|   531k|void TLS_Data_Reader::assert_at_least(size_t n) const {
   15|   531k|   const size_t left = remaining_bytes();
   16|   531k|   if(left < n) {
  ------------------
  |  Branch (16:7): [True: 470, False: 530k]
  ------------------
   17|    470|      throw_decode_error(fmt("Expected {} bytes remaining, only {} left", n, left));
   18|    470|   }
   19|   531k|}
_ZNK5Botan3TLS15TLS_Data_Reader18throw_decode_errorENSt3__117basic_string_viewIcNS2_11char_traitsIcEEEE:
   21|    574|void TLS_Data_Reader::throw_decode_error(std::string_view why) const {
   22|    574|   throw Decoding_Error(fmt("Invalid {}: {}", m_typename, why));
   23|    574|}

_ZN5Botan3TLS16Signature_SchemeC2Ev:
  115|  2.50k|Signature_Scheme::Signature_Scheme() : m_code(NONE) {}
_ZN5Botan3TLS16Signature_SchemeC2Et:
  117|  5.34k|Signature_Scheme::Signature_Scheme(uint16_t wire_code) : Signature_Scheme(Signature_Scheme::Code(wire_code)) {}
_ZN5Botan3TLS16Signature_SchemeC2ENS1_4CodeE:
  119|  5.34k|Signature_Scheme::Signature_Scheme(Signature_Scheme::Code wire_code) : m_code(wire_code) {}
_ZNK5Botan3TLS16Signature_Scheme12is_availableEv:
  121|  2.45k|bool Signature_Scheme::is_available() const noexcept {
  122|  2.45k|   switch(m_code) {
  123|    221|      case RSA_PSS_SHA384:
  ------------------
  |  Branch (123:7): [True: 221, False: 2.23k]
  ------------------
  124|    680|      case RSA_PSS_SHA256:
  ------------------
  |  Branch (124:7): [True: 459, False: 2.00k]
  ------------------
  125|    957|      case RSA_PSS_SHA512:
  ------------------
  |  Branch (125:7): [True: 277, False: 2.18k]
  ------------------
  126|    958|      case RSA_PKCS1_SHA384:
  ------------------
  |  Branch (126:7): [True: 1, False: 2.45k]
  ------------------
  127|    959|      case RSA_PKCS1_SHA512:
  ------------------
  |  Branch (127:7): [True: 1, False: 2.45k]
  ------------------
  128|    962|      case RSA_PKCS1_SHA256:
  ------------------
  |  Branch (128:7): [True: 3, False: 2.45k]
  ------------------
  129|  1.15k|      case ECDSA_BRAINPOOL384R1_TLS13_SHA384:
  ------------------
  |  Branch (129:7): [True: 196, False: 2.26k]
  ------------------
  130|  1.35k|      case ECDSA_BRAINPOOL256R1_TLS13_SHA256:
  ------------------
  |  Branch (130:7): [True: 194, False: 2.26k]
  ------------------
  131|  1.57k|      case ECDSA_BRAINPOOL512R1_TLS13_SHA512:
  ------------------
  |  Branch (131:7): [True: 219, False: 2.24k]
  ------------------
  132|  1.76k|      case ECDSA_SECP384R1_TLS13_SHA384:
  ------------------
  |  Branch (132:7): [True: 194, False: 2.26k]
  ------------------
  133|  2.04k|      case ECDSA_SECP521R1_TLS13_SHA512:
  ------------------
  |  Branch (133:7): [True: 282, False: 2.17k]
  ------------------
  134|  2.36k|      case ECDSA_SECP256R1_TLS13_SHA256:
  ------------------
  |  Branch (134:7): [True: 319, False: 2.14k]
  ------------------
  135|  2.36k|         return true;
  136|     93|      default:
  ------------------
  |  Branch (136:7): [True: 93, False: 2.36k]
  ------------------
  137|     93|         return false;
  138|  2.45k|   }
  139|  2.45k|}
_ZNK5Botan3TLS16Signature_Scheme6is_setEv:
  141|  2.46k|bool Signature_Scheme::is_set() const noexcept {
  142|  2.46k|   return m_code != NONE;
  143|  2.46k|}
_ZNK5Botan3TLS16Signature_Scheme18is_compatible_withERKNS0_16Protocol_VersionE:
  400|  2.36k|bool Signature_Scheme::is_compatible_with(const Protocol_Version& protocol_version) const noexcept {
  401|       |   // RFC 8446 4.4.3:
  402|       |   //   The SHA-1 algorithm MUST NOT be used in any signatures of
  403|       |   //   CertificateVerify messages.
  404|       |   //
  405|       |   // Note that Botan enforces that for TLS 1.2 as well.
  406|  2.36k|   if(m_code == RSA_PKCS1_SHA1 || m_code == ECDSA_SHA1) {
  ------------------
  |  Branch (406:7): [True: 0, False: 2.36k]
  |  Branch (406:35): [True: 0, False: 2.36k]
  ------------------
  407|      0|      return false;
  408|      0|   }
  409|       |
  410|       |   // RFC 8446 4.4.3:
  411|       |   //   RSA signatures MUST use an RSASSA-PSS algorithm, regardless of whether
  412|       |   //   RSASSA-PKCS1-v1_5 algorithms appear in "signature_algorithms".
  413|       |   //
  414|       |   // Note that this is enforced for TLS 1.3 and above only.
  415|  2.36k|   if(!protocol_version.is_pre_tls_13() && (m_code == RSA_PKCS1_SHA1 || m_code == RSA_PKCS1_SHA256 ||
  ------------------
  |  Branch (415:7): [True: 2.36k, False: 0]
  |  Branch (415:45): [True: 0, False: 2.36k]
  |  Branch (415:73): [True: 3, False: 2.36k]
  ------------------
  416|  2.36k|                                            m_code == RSA_PKCS1_SHA384 || m_code == RSA_PKCS1_SHA512)) {
  ------------------
  |  Branch (416:45): [True: 1, False: 2.36k]
  |  Branch (416:75): [True: 1, False: 2.36k]
  ------------------
  417|      5|      return false;
  418|      5|   }
  419|       |
  420|  2.36k|   return true;
  421|  2.36k|}

_ZNK5Botan3TLS16Protocol_Version9to_stringEv:
   34|     78|std::string Protocol_Version::to_string() const {
   35|     78|   const uint8_t maj = major_version();
   36|     78|   const uint8_t min = minor_version();
   37|       |
   38|     78|   if(maj == 3 && min == 0) {
  ------------------
  |  Branch (38:7): [True: 17, False: 61]
  |  Branch (38:19): [True: 2, False: 15]
  ------------------
   39|      2|      return "SSL v3";
   40|      2|   }
   41|       |
   42|     76|   if(maj == 3 && min >= 1) {  // TLS v1.x
  ------------------
  |  Branch (42:7): [True: 15, False: 61]
  |  Branch (42:19): [True: 15, False: 0]
  ------------------
   43|     15|      return "TLS v1." + std::to_string(min - 1);
   44|     15|   }
   45|       |
   46|     61|   if(maj == 254) {  // DTLS 1.x
  ------------------
  |  Branch (46:7): [True: 11, False: 50]
  ------------------
   47|     11|      return "DTLS v1." + std::to_string(255 - min);
   48|     11|   }
   49|       |
   50|       |   // Some very new or very old protocol (or bogus data)
   51|     50|   return "Unknown " + std::to_string(maj) + "." + std::to_string(min);
   52|     61|}
_ZNK5Botan3TLS16Protocol_Version20is_datagram_protocolEv:
   54|  68.6k|bool Protocol_Version::is_datagram_protocol() const {
   55|  68.6k|   return major_version() > 250;
   56|  68.6k|}
_ZNK5Botan3TLS16Protocol_Version13is_pre_tls_13Ev:
   58|  15.8k|bool Protocol_Version::is_pre_tls_13() const {
   59|  15.8k|   return (!is_datagram_protocol() && *this <= Protocol_Version::TLS_V12) ||
  ------------------
  |  Branch (59:12): [True: 11.1k, False: 4.66k]
  |  Branch (59:39): [True: 7.80k, False: 3.33k]
  ------------------
   60|  8.00k|          (is_datagram_protocol() && *this <= Protocol_Version::DTLS_V12);
  ------------------
  |  Branch (60:12): [True: 4.66k, False: 3.33k]
  |  Branch (60:38): [True: 4.65k, False: 18]
  ------------------
   61|  15.8k|}
_ZNK5Botan3TLS16Protocol_Version18is_tls_13_or_laterEv:
   63|    366|bool Protocol_Version::is_tls_13_or_later() const {
   64|    366|   return (!is_datagram_protocol() && *this >= Protocol_Version::TLS_V13) ||
  ------------------
  |  Branch (64:12): [True: 269, False: 97]
  |  Branch (64:39): [True: 16, False: 253]
  ------------------
   65|    350|          (is_datagram_protocol() && *this >= Protocol_Version::DTLS_V13);
  ------------------
  |  Branch (65:12): [True: 97, False: 253]
  |  Branch (65:38): [True: 11, False: 86]
  ------------------
   66|    366|}
_ZNK5Botan3TLS16Protocol_VersiongtERKS1_:
   68|  8.97k|bool Protocol_Version::operator>(const Protocol_Version& other) const {
   69|  8.97k|   if(this->is_datagram_protocol() != other.is_datagram_protocol()) {
  ------------------
  |  Branch (69:7): [True: 0, False: 8.97k]
  ------------------
   70|      0|      throw TLS_Exception(Alert::ProtocolVersion, "Version comparing " + to_string() + " with " + other.to_string());
   71|      0|   }
   72|       |
   73|  8.97k|   if(this->is_datagram_protocol()) {
  ------------------
  |  Branch (73:7): [True: 1.97k, False: 7.00k]
  ------------------
   74|  1.97k|      return m_version < other.m_version;  // goes backwards
   75|  1.97k|   }
   76|       |
   77|  7.00k|   return m_version > other.m_version;
   78|  8.97k|}

_ZN5Botan15allocate_memoryEmm:
   21|  64.9k|BOTAN_MALLOC_FN void* allocate_memory(size_t elems, size_t elem_size) {
   22|  64.9k|   if(elems == 0 || elem_size == 0) {
  ------------------
  |  Branch (22:7): [True: 0, False: 64.9k]
  |  Branch (22:21): [True: 0, False: 64.9k]
  ------------------
   23|      0|      return nullptr;
   24|      0|   }
   25|       |
   26|       |   // Some calloc implementations do not check for overflow (?!?)
   27|  64.9k|   if(!checked_mul(elems, elem_size).has_value()) {
  ------------------
  |  Branch (27:7): [True: 0, False: 64.9k]
  ------------------
   28|      0|      throw std::bad_alloc();
   29|      0|   }
   30|       |
   31|       |#if defined(BOTAN_HAS_LOCKING_ALLOCATOR)
   32|       |   // NOLINTNEXTLINE(*-const-correctness) bug in clang-tidy
   33|       |   if(void* p = mlock_allocator::instance().allocate(elems, elem_size)) {
   34|       |      return p;
   35|       |   }
   36|       |#endif
   37|       |
   38|       |#if defined(BOTAN_TARGET_OS_HAS_ALLOC_CONCEAL)
   39|       |   void* ptr = ::calloc_conceal(elems, elem_size);
   40|       |#else
   41|       |   // NOLINTNEXTLINE(*-const-correctness) bug in clang-tidy
   42|  64.9k|   void* ptr = std::calloc(elems, elem_size);  // NOLINT(*-no-malloc,*-owning-memory)
   43|  64.9k|#endif
   44|  64.9k|   if(ptr == nullptr) {
  ------------------
  |  Branch (44:7): [True: 0, False: 64.9k]
  ------------------
   45|      0|      [[unlikely]] throw std::bad_alloc();
   46|      0|   }
   47|  64.9k|   return ptr;
   48|  64.9k|}
_ZN5Botan17deallocate_memoryEPvmm:
   50|  64.9k|void deallocate_memory(void* p, size_t elems, size_t elem_size) {
   51|  64.9k|   if(p == nullptr) {
  ------------------
  |  Branch (51:7): [True: 0, False: 64.9k]
  ------------------
   52|      0|      [[unlikely]] return;
   53|      0|   }
   54|       |
   55|  64.9k|   secure_scrub_memory(p, elems * elem_size);
   56|       |
   57|       |#if defined(BOTAN_HAS_LOCKING_ALLOCATOR)
   58|       |   if(mlock_allocator::instance().deallocate(p, elems, elem_size)) {
   59|       |      return;
   60|       |   }
   61|       |#endif
   62|       |
   63|  64.9k|   std::free(p);  // NOLINT(*-no-malloc,*-owning-memory)
   64|  64.9k|}

_ZN5Botan22throw_invalid_argumentEPKcS1_S1_:
   23|     16|void throw_invalid_argument(const char* message, const char* func, const char* file) {
   24|     16|   throw Invalid_Argument(fmt("{} in {}:{}", message, func, file));
   25|     16|}

_ZN5Botan19next_utf8_codepointENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEERm:
   53|  1.14k|uint32_t next_utf8_codepoint(std::string_view utf8, size_t& pos) {
   54|  1.14k|   auto read_continuation = [&]() -> uint32_t {
   55|  1.14k|      if(pos >= utf8.size()) {
   56|  1.14k|         throw Decoding_Error("Invalid UTF-8 sequence");
   57|  1.14k|      }
   58|  1.14k|      const uint8_t b = static_cast<uint8_t>(utf8[pos++]);
   59|  1.14k|      if((b & 0xC0) != 0x80) {
   60|  1.14k|         throw Decoding_Error("Invalid UTF-8 sequence");
   61|  1.14k|      }
   62|  1.14k|      return b & 0x3F;
   63|  1.14k|   };
   64|       |
   65|  1.14k|   if(pos >= utf8.size()) {
  ------------------
  |  Branch (65:7): [True: 0, False: 1.14k]
  ------------------
   66|      0|      throw Decoding_Error("Invalid UTF-8 sequence");
   67|      0|   }
   68|  1.14k|   const uint8_t lead = static_cast<uint8_t>(utf8[pos++]);
   69|  1.14k|   uint32_t c = 0;
   70|       |
   71|  1.14k|   if(lead <= 0x7F) {
  ------------------
  |  Branch (71:7): [True: 739, False: 402]
  ------------------
   72|    739|      c = lead;
   73|    739|   } else if((lead & 0xE0) == 0xC0) {
  ------------------
  |  Branch (73:14): [True: 163, False: 239]
  ------------------
   74|    163|      c = (lead & 0x1F) << 6;
   75|    163|      c |= read_continuation();
   76|    163|      if(c < 0x80) {
  ------------------
  |  Branch (76:10): [True: 2, False: 161]
  ------------------
   77|      2|         throw Decoding_Error("Overlong UTF-8 sequence");
   78|      2|      }
   79|    239|   } else if((lead & 0xF0) == 0xE0) {
  ------------------
  |  Branch (79:14): [True: 110, False: 129]
  ------------------
   80|    110|      c = (lead & 0x0F) << 12;
   81|    110|      c |= read_continuation() << 6;
   82|    110|      c |= read_continuation();
   83|    110|      if(c < 0x800) {
  ------------------
  |  Branch (83:10): [True: 6, False: 104]
  ------------------
   84|      6|         throw Decoding_Error("Overlong UTF-8 sequence");
   85|      6|      }
   86|    129|   } else if((lead & 0xF8) == 0xF0) {
  ------------------
  |  Branch (86:14): [True: 107, False: 22]
  ------------------
   87|    107|      c = (lead & 0x07) << 18;
   88|    107|      c |= read_continuation() << 12;
   89|    107|      c |= read_continuation() << 6;
   90|    107|      c |= read_continuation();
   91|    107|      if(c < 0x10000) {
  ------------------
  |  Branch (91:10): [True: 5, False: 102]
  ------------------
   92|      5|         throw Decoding_Error("Overlong UTF-8 sequence");
   93|      5|      }
   94|    107|   } else {
   95|     22|      throw Decoding_Error("Invalid UTF-8 sequence");
   96|     22|   }
   97|       |
   98|  1.10k|   if(c > 0x10FFFF) {
  ------------------
  |  Branch (98:7): [True: 2, False: 1.10k]
  ------------------
   99|      2|      throw Decoding_Error("UTF-8 sequence encodes value outside Unicode range");
  100|      2|   }
  101|  1.10k|   if(c >= 0xD800 && c < 0xE000) {
  ------------------
  |  Branch (101:7): [True: 128, False: 976]
  |  Branch (101:22): [True: 12, False: 116]
  ------------------
  102|     12|      throw Decoding_Error("UTF-8 sequence encodes surrogate code point");
  103|     12|   }
  104|       |
  105|  1.09k|   return c;
  106|  1.10k|}
_ZN5Botan13is_valid_utf8ENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEE:
  108|    241|bool is_valid_utf8(std::string_view utf8) {
  109|    241|   try {
  110|    241|      size_t pos = 0;
  111|  1.38k|      while(pos < utf8.size()) {
  ------------------
  |  Branch (111:13): [True: 1.14k, False: 241]
  ------------------
  112|  1.14k|         const uint32_t c = next_utf8_codepoint(utf8, pos);
  113|  1.14k|         BOTAN_UNUSED(c);
  ------------------
  |  |  151|  1.14k|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
  114|  1.14k|      }
  115|    241|   } catch(Decoding_Error&) {
  116|     58|      return false;
  117|     58|   }
  118|    183|   return true;
  119|    241|}
_ZN5Botan12ucs2_to_utf8ENSt3__14spanIKhLm18446744073709551615EEE:
  121|    125|std::string ucs2_to_utf8(std::span<const uint8_t> ucs2) {
  122|    125|   if(ucs2.size() % 2 != 0) {
  ------------------
  |  Branch (122:7): [True: 1, False: 124]
  ------------------
  123|      1|      throw Decoding_Error("Invalid length for UCS-2 string");
  124|      1|   }
  125|       |
  126|    124|   const size_t chars = ucs2.size() / 2;
  127|       |
  128|    124|   std::string s;
  129|  1.49k|   for(size_t i = 0; i != chars; ++i) {
  ------------------
  |  Branch (129:22): [True: 1.36k, False: 124]
  ------------------
  130|  1.36k|      const uint32_t c = load_be<uint16_t>(ucs2.data(), i);
  131|  1.36k|      append_utf8_for(s, c);
  132|  1.36k|   }
  133|       |
  134|    124|   return s;
  135|    125|}
_ZN5Botan12ucs4_to_utf8ENSt3__14spanIKhLm18446744073709551615EEE:
  155|     66|std::string ucs4_to_utf8(std::span<const uint8_t> ucs4) {
  156|     66|   if(ucs4.size() % 4 != 0) {
  ------------------
  |  Branch (156:7): [True: 1, False: 65]
  ------------------
  157|      1|      throw Decoding_Error("Invalid length for UCS-4 string");
  158|      1|   }
  159|       |
  160|     65|   const size_t chars = ucs4.size() / 4;
  161|       |
  162|     65|   std::string s;
  163|    247|   for(size_t i = 0; i != chars; ++i) {
  ------------------
  |  Branch (163:22): [True: 182, False: 65]
  ------------------
  164|    182|      const uint32_t c = load_be<uint32_t>(ucs4.data(), i);
  165|    182|      append_utf8_for(s, c);
  166|    182|   }
  167|       |
  168|     65|   return s;
  169|     66|}
_ZN5Botan14latin1_to_utf8ENSt3__14spanIKhLm18446744073709551615EEE:
  190|    231|std::string latin1_to_utf8(std::span<const uint8_t> chars) {
  191|    231|   std::string s;
  192|  4.74k|   for(const uint8_t b : chars) {
  ------------------
  |  Branch (192:24): [True: 4.74k, False: 231]
  ------------------
  193|  4.74k|      append_utf8_for(s, static_cast<uint32_t>(b));
  194|  4.74k|   }
  195|    231|   return s;
  196|    231|}
_ZN5Botan21is_ascii_control_charEc:
  198|     36|bool is_ascii_control_char(char c) {
  199|     36|   const uint8_t b = static_cast<uint8_t>(c);
  200|     36|   return b < 0x20 || b == 0x7F;
  ------------------
  |  Branch (200:11): [True: 13, False: 23]
  |  Branch (200:23): [True: 0, False: 23]
  ------------------
  201|     36|}
_ZN5Botan23format_char_for_displayEc:
  243|     36|std::string format_char_for_display(char c) {
  244|     36|   std::string out;
  245|     36|   out += '\'';
  246|       |
  247|     36|   if(c == '\t') {
  ------------------
  |  Branch (247:7): [True: 0, False: 36]
  ------------------
  248|      0|      out += "\\t";
  249|     36|   } else if(c == '\n') {
  ------------------
  |  Branch (249:14): [True: 0, False: 36]
  ------------------
  250|      0|      out += "\\n";
  251|     36|   } else if(c == '\r') {
  ------------------
  |  Branch (251:14): [True: 0, False: 36]
  ------------------
  252|      0|      out += "\\r";
  253|     36|   } else if(is_ascii_control_char(c) || static_cast<uint8_t>(c) >= 0x80) {
  ------------------
  |  Branch (253:14): [True: 13, False: 23]
  |  Branch (253:42): [True: 15, False: 8]
  ------------------
  254|     28|      const auto b = static_cast<uint8_t>(c);
  255|     28|      out += "\\x";
  256|     28|      out += nibble_to_hex(b >> 4);
  257|     28|      out += nibble_to_hex(b);
  258|     28|   } else {
  259|      8|      out += c;
  260|      8|   }
  261|       |
  262|     36|   out += '\'';
  263|       |
  264|     36|   return out;
  265|     36|}
charset.cpp:_ZZN5Botan19next_utf8_codepointENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEERmENK3$_0clEv:
   54|    699|   auto read_continuation = [&]() -> uint32_t {
   55|    699|      if(pos >= utf8.size()) {
  ------------------
  |  Branch (55:10): [True: 5, False: 694]
  ------------------
   56|      5|         throw Decoding_Error("Invalid UTF-8 sequence");
   57|      5|      }
   58|    694|      const uint8_t b = static_cast<uint8_t>(utf8[pos++]);
   59|    694|      if((b & 0xC0) != 0x80) {
  ------------------
  |  Branch (59:10): [True: 4, False: 690]
  ------------------
   60|      4|         throw Decoding_Error("Invalid UTF-8 sequence");
   61|      4|      }
   62|    690|      return b & 0x3F;
   63|    694|   };
charset.cpp:_ZN5Botan12_GLOBAL__N_115append_utf8_forERNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEj:
   17|  6.29k|void append_utf8_for(std::string& s, uint32_t c) {
   18|  6.29k|   if(c >= 0xD800 && c < 0xE000) {
  ------------------
  |  Branch (18:7): [True: 453, False: 5.84k]
  |  Branch (18:22): [True: 6, False: 447]
  ------------------
   19|      6|      throw Decoding_Error("Invalid Unicode character");
   20|      6|   }
   21|       |
   22|  6.28k|   if(c <= 0x7F) {
  ------------------
  |  Branch (22:7): [True: 4.14k, False: 2.14k]
  ------------------
   23|  4.14k|      const uint8_t b0 = static_cast<uint8_t>(c);
   24|  4.14k|      s.push_back(static_cast<char>(b0));
   25|  4.14k|   } else if(c <= 0x7FF) {
  ------------------
  |  Branch (25:14): [True: 1.30k, False: 838]
  ------------------
   26|  1.30k|      const uint8_t b0 = 0xC0 | static_cast<uint8_t>(c >> 6);
   27|  1.30k|      const uint8_t b1 = 0x80 | static_cast<uint8_t>(c & 0x3F);
   28|  1.30k|      s.push_back(static_cast<char>(b0));
   29|  1.30k|      s.push_back(static_cast<char>(b1));
   30|  1.30k|   } else if(c <= 0xFFFF) {
  ------------------
  |  Branch (30:14): [True: 696, False: 142]
  ------------------
   31|    696|      const uint8_t b0 = 0xE0 | static_cast<uint8_t>(c >> 12);
   32|    696|      const uint8_t b1 = 0x80 | static_cast<uint8_t>((c >> 6) & 0x3F);
   33|    696|      const uint8_t b2 = 0x80 | static_cast<uint8_t>(c & 0x3F);
   34|    696|      s.push_back(static_cast<char>(b0));
   35|    696|      s.push_back(static_cast<char>(b1));
   36|    696|      s.push_back(static_cast<char>(b2));
   37|    696|   } else if(c <= 0x10FFFF) {
  ------------------
  |  Branch (37:14): [True: 107, False: 35]
  ------------------
   38|    107|      const uint8_t b0 = 0xF0 | static_cast<uint8_t>(c >> 18);
   39|    107|      const uint8_t b1 = 0x80 | static_cast<uint8_t>((c >> 12) & 0x3F);
   40|    107|      const uint8_t b2 = 0x80 | static_cast<uint8_t>((c >> 6) & 0x3F);
   41|    107|      const uint8_t b3 = 0x80 | static_cast<uint8_t>(c & 0x3F);
   42|    107|      s.push_back(static_cast<char>(b0));
   43|    107|      s.push_back(static_cast<char>(b1));
   44|    107|      s.push_back(static_cast<char>(b2));
   45|    107|      s.push_back(static_cast<char>(b3));
   46|    107|   } else {
   47|     35|      throw Decoding_Error("Invalid Unicode character");
   48|     35|   }
   49|  6.28k|}

_ZN5Botan5CPUID10CPUID_DataC2Ev:
   80|      1|CPUID::CPUID_Data::CPUID_Data() {
   81|       |   // NOLINTBEGIN(*-prefer-member-initializer)
   82|      1|#if defined(BOTAN_HAS_CPUID_DETECTION)
   83|      1|   m_processor_features = detect_cpu_features(~cleared_cpuid_bits());
   84|       |#else
   85|       |   m_processor_features = 0;
   86|       |#endif
   87|       |   // NOLINTEND(*-prefer-member-initializer)
   88|      1|}
cpuid.cpp:_ZN5Botan12_GLOBAL__N_118cleared_cpuid_bitsEv:
   59|      1|uint32_t cleared_cpuid_bits() {
   60|      1|   uint32_t cleared = 0;
   61|       |
   62|      1|   #if defined(BOTAN_HAS_OS_UTILS)
   63|      1|   std::string clear_cpuid_env;
   64|      1|   if(OS::read_env_variable(clear_cpuid_env, "BOTAN_CLEAR_CPUID")) {
  ------------------
  |  Branch (64:7): [True: 0, False: 1]
  ------------------
   65|      0|      for(const auto& cpuid : split_on(clear_cpuid_env, ',')) {
  ------------------
  |  Branch (65:29): [True: 0, False: 0]
  ------------------
   66|      0|         if(auto bit = CPUID::bit_from_string(cpuid)) {
  ------------------
  |  Branch (66:18): [True: 0, False: 0]
  ------------------
   67|      0|            cleared |= bit->as_u32();
   68|      0|         }
   69|      0|      }
   70|      0|   }
   71|      1|   #endif
   72|       |
   73|      1|   return cleared;
   74|      1|}

_ZN5Botan5CPUID10CPUID_Data19detect_cpu_featuresEj:
   62|      1|uint32_t CPUID::CPUID_Data::detect_cpu_features(uint32_t allowed) {
   63|      1|   enum class x86_CPUID_1_bits : uint64_t {
   64|      1|      RDTSC = (1ULL << 4),
   65|      1|      SSE2 = (1ULL << 26),
   66|      1|      CLMUL = (1ULL << 33),
   67|      1|      SSSE3 = (1ULL << 41),
   68|      1|      SSE41 = (1ULL << 51),
   69|      1|      AESNI = (1ULL << 57),
   70|       |      // AVX + OSXSAVE
   71|      1|      OSXSAVE = (1ULL << 59) | (1ULL << 60),
   72|      1|      RDRAND = (1ULL << 62)
   73|      1|   };
   74|       |
   75|      1|   enum class x86_CPUID_7_bits : uint64_t {
   76|      1|      BMI1 = (1ULL << 3),
   77|      1|      AVX2 = (1ULL << 5),
   78|      1|      BMI2 = (1ULL << 8),
   79|      1|      BMI_1_AND_2 = BMI1 | BMI2,
   80|      1|      AVX512_F = (1ULL << 16),
   81|      1|      AVX512_DQ = (1ULL << 17),
   82|      1|      RDSEED = (1ULL << 18),
   83|      1|      ADX = (1ULL << 19),
   84|      1|      AVX512_IFMA = (1ULL << 21),
   85|      1|      SHA = (1ULL << 29),
   86|      1|      AVX512_BW = (1ULL << 30),
   87|      1|      AVX512_VL = (1ULL << 31),
   88|      1|      AVX512_VBMI = (1ULL << 33),
   89|      1|      AVX512_VBMI2 = (1ULL << 38),
   90|      1|      GFNI = (1ULL << 40),
   91|      1|      AVX512_VAES = (1ULL << 41),
   92|      1|      AVX512_VCLMUL = (1ULL << 42),
   93|      1|      AVX512_VBITALG = (1ULL << 44),
   94|       |
   95|       |      /*
   96|       |      We only enable AVX512 support if all of the below flags are available
   97|       |
   98|       |      This is more than we strictly need for most uses, however it also has
   99|       |      the effect of preventing execution of AVX512 codepaths on cores that
  100|       |      have serious downclocking problems when AVX512 code executes,
  101|       |      especially Intel Skylake.
  102|       |
  103|       |      VBMI2/VBITALG are the key flags here as they restrict us to Intel Ice
  104|       |      Lake/Rocket Lake, or AMD Zen4, all of which do not have penalties for
  105|       |      executing AVX512.
  106|       |
  107|       |      There is nothing stopping some future processor from supporting the
  108|       |      above flags and having AVX512 penalties, but maybe you should not have
  109|       |      bought such a processor.
  110|       |      */
  111|      1|      AVX512_PROFILE =
  112|      1|         AVX512_F | AVX512_DQ | AVX512_IFMA | AVX512_BW | AVX512_VL | AVX512_VBMI | AVX512_VBMI2 | AVX512_VBITALG,
  113|      1|   };
  114|       |
  115|       |   // NOLINTNEXTLINE(performance-enum-size)
  116|      1|   enum class x86_CPUID_7_1_bits : uint64_t {
  117|      1|      SHA512 = (1 << 0),
  118|      1|      SM3 = (1 << 1),
  119|      1|      SM4 = (1 << 2),
  120|      1|   };
  121|       |
  122|      1|   uint32_t feat = 0;
  123|      1|   uint32_t cpuid[4] = {0};
  124|      1|   bool has_os_ymm_support = false;
  125|      1|   bool has_os_zmm_support = false;
  126|       |
  127|       |   // CPUID 0: vendor identification, max sublevel
  128|      1|   invoke_cpuid(0, cpuid);
  129|       |
  130|      1|   const uint32_t max_supported_sublevel = cpuid[0];
  131|       |
  132|      1|   if(max_supported_sublevel >= 1) {
  ------------------
  |  Branch (132:7): [True: 1, False: 0]
  ------------------
  133|       |      // CPUID 1: feature bits
  134|      1|      invoke_cpuid(1, cpuid);
  135|      1|      const uint64_t flags0 = (static_cast<uint64_t>(cpuid[2]) << 32) | cpuid[3];
  136|       |
  137|      1|      feat |= if_set(flags0, x86_CPUID_1_bits::RDTSC, CPUFeature::Bit::RDTSC, allowed);
  138|       |
  139|      1|      feat |= if_set(flags0, x86_CPUID_1_bits::RDRAND, CPUFeature::Bit::RDRAND, allowed);
  140|       |
  141|      1|      feat |= if_set(flags0, x86_CPUID_1_bits::SSE2, CPUFeature::Bit::SSE2, allowed);
  142|       |
  143|      1|      if(is_set(feat, CPUFeature::Bit::SSE2)) {
  ------------------
  |  Branch (143:10): [True: 1, False: 0]
  ------------------
  144|      1|         feat |= if_set(flags0, x86_CPUID_1_bits::SSSE3, CPUFeature::Bit::SSSE3, allowed);
  145|       |
  146|      1|         if(is_set(feat, CPUFeature::Bit::SSSE3)) {
  ------------------
  |  Branch (146:13): [True: 1, False: 0]
  ------------------
  147|      1|            feat |= if_set(flags0, x86_CPUID_1_bits::CLMUL, CPUFeature::Bit::CLMUL, allowed);
  148|      1|            feat |= if_set(flags0, x86_CPUID_1_bits::AESNI, CPUFeature::Bit::AESNI, allowed);
  149|      1|         }
  150|       |
  151|      1|         const uint64_t osxsave64 = static_cast<uint64_t>(x86_CPUID_1_bits::OSXSAVE);
  152|      1|         if((flags0 & osxsave64) == osxsave64) {
  ------------------
  |  Branch (152:13): [True: 1, False: 0]
  ------------------
  153|      1|            const uint64_t xcr_flags = xgetbv();
  154|      1|            if((xcr_flags & 0x6) == 0x6) {
  ------------------
  |  Branch (154:16): [True: 1, False: 0]
  ------------------
  155|      1|               has_os_ymm_support = true;
  156|      1|               has_os_zmm_support = (xcr_flags & 0xE0) == 0xE0;
  157|      1|            }
  158|      1|         }
  159|      1|      }
  160|      1|   }
  161|       |
  162|      1|   if(max_supported_sublevel >= 7) {
  ------------------
  |  Branch (162:7): [True: 1, False: 0]
  ------------------
  163|      1|      clear_mem(cpuid, 4);
  164|      1|      invoke_cpuid_sublevel(7, 0, cpuid);
  165|       |
  166|      1|      const uint64_t flags7 = (static_cast<uint64_t>(cpuid[2]) << 32) | cpuid[1];
  167|       |
  168|      1|      clear_mem(cpuid, 4);
  169|      1|      invoke_cpuid_sublevel(7, 1, cpuid);
  170|      1|      const uint32_t flags7_1 = cpuid[0];
  171|       |
  172|      1|      feat |= if_set(flags7, x86_CPUID_7_bits::RDSEED, CPUFeature::Bit::RDSEED, allowed);
  173|      1|      feat |= if_set(flags7, x86_CPUID_7_bits::ADX, CPUFeature::Bit::ADX, allowed);
  174|       |
  175|       |      /*
  176|       |      We only set the BMI bit if both BMI1 and BMI2 are supported, since
  177|       |      typically we want to use both extensions in the same code.
  178|       |      */
  179|      1|      feat |= if_set(flags7, x86_CPUID_7_bits::BMI_1_AND_2, CPUFeature::Bit::BMI, allowed);
  180|       |
  181|      1|      if(is_set(feat, CPUFeature::Bit::SSSE3)) {
  ------------------
  |  Branch (181:10): [True: 1, False: 0]
  ------------------
  182|      1|         feat |= if_set(flags7, x86_CPUID_7_bits::SHA, CPUFeature::Bit::SHA, allowed);
  183|      1|         feat |= if_set(flags7_1, x86_CPUID_7_1_bits::SM3, CPUFeature::Bit::SM3, allowed);
  184|       |
  185|       |         // We only consider AVX2 if SSSE3 is supported
  186|      1|         if(has_os_ymm_support) {
  ------------------
  |  Branch (186:13): [True: 1, False: 0]
  ------------------
  187|      1|            feat |= if_set(flags7, x86_CPUID_7_bits::AVX2, CPUFeature::Bit::AVX2, allowed);
  188|       |
  189|      1|            if(is_set(feat, CPUFeature::Bit::AVX2)) {
  ------------------
  |  Branch (189:16): [True: 1, False: 0]
  ------------------
  190|      1|               feat |= if_set(flags7, x86_CPUID_7_bits::GFNI, CPUFeature::Bit::GFNI, allowed);
  191|      1|               feat |= if_set(flags7, x86_CPUID_7_bits::AVX512_VAES, CPUFeature::Bit::AVX2_AES, allowed);
  192|      1|               feat |= if_set(flags7, x86_CPUID_7_bits::AVX512_VCLMUL, CPUFeature::Bit::AVX2_CLMUL, allowed);
  193|      1|               feat |= if_set(flags7_1, x86_CPUID_7_1_bits::SHA512, CPUFeature::Bit::SHA512, allowed);
  194|      1|               feat |= if_set(flags7_1, x86_CPUID_7_1_bits::SM4, CPUFeature::Bit::SM4, allowed);
  195|       |
  196|       |               // Likewise we only consider AVX-512 if AVX2 is supported
  197|      1|               if(has_os_zmm_support) {
  ------------------
  |  Branch (197:19): [True: 0, False: 1]
  ------------------
  198|      0|                  feat |= if_set(flags7, x86_CPUID_7_bits::AVX512_PROFILE, CPUFeature::Bit::AVX512, allowed);
  199|       |
  200|      0|                  if(is_set(feat, CPUFeature::Bit::AVX512)) {
  ------------------
  |  Branch (200:22): [True: 0, False: 0]
  ------------------
  201|      0|                     feat |= if_set(flags7, x86_CPUID_7_bits::AVX512_VAES, CPUFeature::Bit::AVX512_AES, allowed);
  202|      0|                     feat |= if_set(flags7, x86_CPUID_7_bits::AVX512_VCLMUL, CPUFeature::Bit::AVX512_CLMUL, allowed);
  203|      0|                  }
  204|      0|               }
  205|      1|            }
  206|      1|         }
  207|      1|      }
  208|      1|   }
  209|       |
  210|       |/*
  211|       |   * If we don't have access to CPUID, we can still safely assume that
  212|       |   * any x86-64 processor has SSE2 and RDTSC
  213|       |   */
  214|      1|#if defined(BOTAN_TARGET_ARCH_IS_X86_64)
  215|      1|   if(feat == 0) {
  ------------------
  |  Branch (215:7): [True: 0, False: 1]
  ------------------
  216|      0|      feat |= CPUFeature::Bit::SSE2 & allowed;
  217|      0|      feat |= CPUFeature::Bit::RDTSC & allowed;
  218|      0|   }
  219|      1|#endif
  220|       |
  221|      1|   return feat;
  222|      1|}
cpuid_x86.cpp:_ZN5Botan12_GLOBAL__N_112invoke_cpuidEjPj:
   24|      2|void invoke_cpuid(uint32_t type, uint32_t out[4]) {
   25|      2|   clear_mem(out, 4);
   26|       |
   27|      2|#if defined(BOTAN_USE_GCC_INLINE_ASM)
   28|       |   // NOLINTNEXTLINE(*-no-assembler)
   29|      2|   asm volatile("cpuid\n\t" : "=a"(out[0]), "=b"(out[1]), "=c"(out[2]), "=d"(out[3]) : "0"(type));
   30|       |
   31|       |#elif defined(BOTAN_BUILD_COMPILER_IS_MSVC)
   32|       |   __cpuid((int*)out, type);
   33|       |
   34|       |#else
   35|       |   BOTAN_UNUSED(type);
   36|       |   #warning "No way of calling x86 cpuid instruction for this compiler"
   37|       |#endif
   38|      2|}
cpuid_x86.cpp:_ZN5Botan12_GLOBAL__N_16xgetbvEv:
   56|      1|BOTAN_FUNC_ISA("xsave") uint64_t xgetbv() {
   57|       |   return _xgetbv(0);
   58|      1|}
cpuid_x86.cpp:_ZN5Botan12_GLOBAL__N_121invoke_cpuid_sublevelEjjPj:
   40|      2|void invoke_cpuid_sublevel(uint32_t type, uint32_t level, uint32_t out[4]) {
   41|      2|   clear_mem(out, 4);
   42|       |
   43|      2|#if defined(BOTAN_USE_GCC_INLINE_ASM)
   44|       |   // NOLINTNEXTLINE(*-no-assembler)
   45|      2|   asm volatile("cpuid\n\t" : "=a"(out[0]), "=b"(out[1]), "=c"(out[2]), "=d"(out[3]) : "0"(type), "2"(level));
   46|       |
   47|       |#elif defined(BOTAN_BUILD_COMPILER_IS_MSVC)
   48|       |   __cpuidex((int*)out, type, level);
   49|       |
   50|       |#else
   51|       |   BOTAN_UNUSED(type, level);
   52|       |   #warning "No way of calling x86 cpuid instruction for this compiler"
   53|       |#endif
   54|      2|}

_ZN5Botan10DataSource9read_byteERh:
   27|  42.3k|size_t DataSource::read_byte(uint8_t& out) {
   28|  42.3k|   return read(&out, 1);
   29|  42.3k|}
_ZN5Botan10DataSource9read_byteEv:
   34|  92.2k|std::optional<uint8_t> DataSource::read_byte() {
   35|  92.2k|   uint8_t b = 0;
   36|  92.2k|   if(this->read(&b, 1) == 1) {
  ------------------
  |  Branch (36:7): [True: 88.1k, False: 4.15k]
  ------------------
   37|  88.1k|      return b;
   38|  88.1k|   } else {
   39|  4.15k|      return {};
   40|  4.15k|   }
   41|  92.2k|}
_ZNK5Botan10DataSource9peek_byteERh:
   46|  4.24k|size_t DataSource::peek_byte(uint8_t& out) const {
   47|  4.24k|   return peek(&out, 1, 0);
   48|  4.24k|}
_ZN5Botan17DataSource_Memory4readEPhm:
   73|   104k|size_t DataSource_Memory::read(uint8_t out[], size_t length) {
   74|   104k|   const size_t got = std::min<size_t>(m_source.size() - m_offset, length);
   75|   104k|   copy_mem(out, m_source.data() + m_offset, got);
   76|   104k|   m_offset += got;
   77|   104k|   return got;
   78|   104k|}
_ZN5Botan17DataSource_Memory15check_availableEm:
   80|  18.5k|bool DataSource_Memory::check_available(size_t n) {
   81|  18.5k|   return (n <= (m_source.size() - m_offset));
   82|  18.5k|}
_ZNK5Botan17DataSource_Memory4peekEPhmm:
   87|  8.31k|size_t DataSource_Memory::peek(uint8_t out[], size_t length, size_t peek_offset) const {
   88|  8.31k|   const size_t bytes_left = m_source.size() - m_offset;
   89|  8.31k|   if(peek_offset >= bytes_left) {
  ------------------
  |  Branch (89:7): [True: 1, False: 8.30k]
  ------------------
   90|      1|      return 0;
   91|      1|   }
   92|       |
   93|  8.30k|   const size_t got = std::min(bytes_left - peek_offset, length);
   94|  8.30k|   copy_mem(out, &m_source[m_offset + peek_offset], got);
   95|  8.30k|   return got;
   96|  8.31k|}
_ZNK5Botan17DataSource_Memory11end_of_dataEv:
  101|  9.36k|bool DataSource_Memory::end_of_data() const {
  102|  9.36k|   return (m_offset == m_source.size());
  103|  9.36k|}

_ZN5Botan9ExceptionC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   71|  9.46k|Exception::Exception(std::string_view msg) : m_msg(msg) {}
_ZN5Botan9ExceptionC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEERKSt9exception:
   73|  4.18k|Exception::Exception(std::string_view msg, const std::exception& e) : m_msg(fmt("{} failed with {}", msg, e.what())) {}
_ZN5Botan9ExceptionC2EPKcNSt3__117basic_string_viewIcNS3_11char_traitsIcEEEE:
   75|      1|Exception::Exception(const char* prefix, std::string_view msg) : m_msg(fmt("{} {}", prefix, msg)) {}
_ZN5Botan16Invalid_ArgumentC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   77|    110|Invalid_Argument::Invalid_Argument(std::string_view msg) : Exception(msg) {}
_ZN5Botan14Decoding_ErrorC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  125|  4.36k|Decoding_Error::Decoding_Error(std::string_view name) : Exception(name) {}
_ZN5Botan14Decoding_ErrorC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEERKSt9exception:
  130|  4.18k|Decoding_Error::Decoding_Error(std::string_view msg, const std::exception& e) : Exception(msg, e) {}
_ZN5Botan15Stream_IO_ErrorC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  135|      1|Stream_IO_Error::Stream_IO_Error(std::string_view err) : Exception("I/O error:", err) {}

_ZN5Botan19secure_scrub_memoryEPvm:
   24|   172k|void secure_scrub_memory(void* ptr, size_t n) {
   25|   172k|   return secure_zeroize_buffer(ptr, n);
   26|   172k|}
_ZN5Botan21secure_zeroize_bufferEPvm:
   28|   213k|void secure_zeroize_buffer(void* ptr, size_t n) {
   29|   213k|   if(n == 0) {
  ------------------
  |  Branch (29:7): [True: 71.0k, False: 142k]
  ------------------
   30|  71.0k|      return;
   31|  71.0k|   }
   32|       |
   33|       |#if defined(BOTAN_TARGET_OS_HAS_RTLSECUREZEROMEMORY)
   34|       |   ::RtlSecureZeroMemory(ptr, n);
   35|       |
   36|       |#elif defined(BOTAN_TARGET_OS_HAS_EXPLICIT_BZERO)
   37|   142k|   ::explicit_bzero(ptr, n);
   38|       |
   39|       |#elif defined(BOTAN_TARGET_OS_HAS_EXPLICIT_MEMSET)
   40|       |   (void)::explicit_memset(ptr, 0, n);
   41|       |
   42|       |#else
   43|       |   /*
   44|       |   * Call memset through a static volatile pointer, which the compiler should
   45|       |   * not elide. This construct should be safe in conforming compilers, but who
   46|       |   * knows. This has been checked to generate the expected code, which saves the
   47|       |   * memset address in the data segment and unconditionally loads and jumps to
   48|       |   * that address, with the following targets:
   49|       |   *
   50|       |   * x86-64: Clang 19, GCC 6, 11, 13, 14
   51|       |   * riscv64: GCC 14
   52|       |   * aarch64: GCC 14
   53|       |   * armv7: GCC 14
   54|       |   *
   55|       |   * Actually all of them generated the expected jump even without marking the
   56|       |   * function pointer as volatile. However this seems worth including as an
   57|       |   * additional precaution.
   58|       |   */
   59|       |   static void* (*const volatile memset_ptr)(void*, int, size_t) = std::memset;
   60|       |   (memset_ptr)(ptr, 0, n);
   61|       |#endif
   62|   142k|}

_ZN5Botan2OS17read_env_variableERNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EE:
  449|      1|bool OS::read_env_variable(std::string& value_out, std::string_view name_view) {
  450|      1|   value_out = "";
  451|       |
  452|      1|   if(running_in_privileged_state()) {
  ------------------
  |  Branch (452:7): [True: 0, False: 1]
  ------------------
  453|      0|      return false;
  454|      0|   }
  455|       |
  456|       |#if defined(BOTAN_TARGET_OS_HAS_WIN32) && \
  457|       |   (defined(BOTAN_BUILD_COMPILER_IS_MSVC) || defined(BOTAN_BUILD_COMPILER_IS_CLANGCL))
  458|       |   const std::string name(name_view);
  459|       |   char val[128] = {0};
  460|       |   size_t req_size = 0;
  461|       |   if(getenv_s(&req_size, val, sizeof(val), name.c_str()) == 0) {
  462|       |      // Microsoft's implementation always writes a terminating \0,
  463|       |      // and includes it in the reported length of the environment variable
  464|       |      // if a value exists.
  465|       |      if(req_size > 0 && val[req_size - 1] == '\0') {
  466|       |         value_out = std::string(val);
  467|       |      } else {
  468|       |         value_out = std::string(val, req_size);
  469|       |      }
  470|       |      return true;
  471|       |   }
  472|       |#else
  473|      1|   const std::string name(name_view);
  474|      1|   if(const char* val = std::getenv(name.c_str())) {
  ------------------
  |  Branch (474:19): [True: 0, False: 1]
  ------------------
  475|      0|      value_out = val;
  476|      0|      return true;
  477|      0|   }
  478|      1|#endif
  479|       |
  480|      1|   return false;
  481|      1|}
os_utils.cpp:_ZN5Botan12_GLOBAL__N_110get_auxvalENSt3__18optionalImEE:
  119|      1|std::optional<unsigned long> get_auxval(std::optional<unsigned long> id) {
  120|      1|   if(id) {
  ------------------
  |  Branch (120:7): [True: 1, False: 0]
  ------------------
  121|      1|#if defined(BOTAN_TARGET_OS_HAS_GETAUXVAL)
  122|      1|      return ::getauxval(*id);
  123|       |#elif defined(BOTAN_TARGET_OS_HAS_ELF_AUX_INFO)
  124|       |      unsigned long auxinfo = 0;
  125|       |      if(::elf_aux_info(static_cast<int>(*id), &auxinfo, sizeof(auxinfo)) == 0) {
  126|       |         return auxinfo;
  127|       |      }
  128|       |#endif
  129|      1|   }
  130|       |
  131|      0|   return {};
  132|      1|}
os_utils.cpp:_ZN5Botan12_GLOBAL__N_127running_in_privileged_stateEv:
  153|      1|bool running_in_privileged_state() {
  154|      1|#if defined(AT_SECURE)
  155|      1|   if(auto at_secure = get_auxval(AT_SECURE)) {
  ------------------
  |  Branch (155:12): [True: 1, False: 0]
  ------------------
  156|      1|      return at_secure != 0;
  157|      1|   }
  158|      0|#endif
  159|       |
  160|      0|#if defined(BOTAN_TARGET_OS_HAS_POSIX1)
  161|      0|   return (::getuid() != ::geteuid()) || (::getgid() != ::getegid());
  ------------------
  |  Branch (161:11): [True: 0, False: 0]
  |  Branch (161:42): [True: 0, False: 0]
  ------------------
  162|       |#else
  163|       |   return false;
  164|       |#endif
  165|      1|}

_ZN5Botan9parse_u32ENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEEb:
   63|  16.7k|std::optional<uint32_t> parse_u32(std::string_view input, bool require_canonical) {
   64|  16.7k|   return parse_decimal_integer<uint32_t>(input, require_canonical);
   65|  16.7k|}
_ZN5Botan9to_u32bitENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEE:
   75|  16.7k|uint32_t to_u32bit(std::string_view input) {
   76|  16.7k|   if(const auto parsed = parse_u32(input)) {
  ------------------
  |  Branch (76:18): [True: 16.7k, False: 11]
  ------------------
   77|  16.7k|      return *parsed;
   78|  16.7k|   } else {
   79|     11|      throw Invalid_Argument(fmt("Failed to parse input '{}' as a 32-bit integer", input));
   80|     11|   }
   81|  16.7k|}
parsing.cpp:_ZN5Botan12_GLOBAL__N_116digit_from_asciiEc:
   22|  39.0k|std::optional<size_t> digit_from_ascii(char c) {
   23|  39.0k|   if(c >= '0' && c <= '9') {
  ------------------
  |  Branch (23:7): [True: 39.0k, False: 5]
  |  Branch (23:19): [True: 39.0k, False: 6]
  ------------------
   24|  39.0k|      return c - '0';
   25|  39.0k|   } else {
   26|     11|      return {};
   27|     11|   }
   28|  39.0k|}
parsing.cpp:_ZN5Botan12_GLOBAL__N_121parse_decimal_integerITkNSt3__117unsigned_integralEjEENS2_8optionalIT_EENS2_17basic_string_viewIcNS2_11char_traitsIcEEEEb:
   31|  16.7k|std::optional<T> parse_decimal_integer(std::string_view input, bool require_canonical) {
   32|  16.7k|   if(input.empty() || input.size() > (std::numeric_limits<T>::digits10 + 1)) {
  ------------------
  |  Branch (32:7): [True: 0, False: 16.7k]
  |  Branch (32:24): [True: 0, False: 16.7k]
  ------------------
   33|      0|      return {};
   34|      0|   }
   35|       |
   36|       |   // The canonical encoding of zero is "0"; no other value starts with a zero
   37|  16.7k|   if(require_canonical && input.size() > 1 && input.front() == '0') {
  ------------------
  |  Branch (37:7): [True: 0, False: 16.7k]
  |  Branch (37:28): [True: 0, False: 0]
  |  Branch (37:48): [True: 0, False: 0]
  ------------------
   38|      0|      return {};
   39|      0|   }
   40|       |
   41|  16.7k|   T accum = 0;
   42|       |
   43|  39.0k|   for(const char c : input) {
  ------------------
  |  Branch (43:21): [True: 39.0k, False: 16.7k]
  ------------------
   44|  39.0k|      if(const auto digit = digit_from_ascii(c)) {
  ------------------
  |  Branch (44:21): [True: 39.0k, False: 11]
  ------------------
   45|  39.0k|         if(accum > (std::numeric_limits<T>::max() - static_cast<T>(*digit)) / 10) {
  ------------------
  |  Branch (45:13): [True: 0, False: 39.0k]
  ------------------
   46|      0|            return {};
   47|      0|         }
   48|  39.0k|         accum = accum * 10 + static_cast<T>(*digit);
   49|  39.0k|      } else {
   50|     11|         return {};
   51|     11|      }
   52|  39.0k|   }
   53|       |
   54|  16.7k|   return accum;
   55|  16.7k|}

_ZN5BotaneqERKNS_7X509_DNES2_:
  338|  1.32k|bool operator==(const X509_DN& dn1, const X509_DN& dn2) {
  339|  1.32k|   return dn1._canonical_bytes() == dn2._canonical_bytes();
  340|  1.32k|}
_ZN5Botan7X509_DN11decode_fromERNS_11BER_DecoderE:
  407|  4.22k|void X509_DN::decode_from(BER_Decoder& source) {
  408|  4.22k|   std::vector<uint8_t> bits;
  409|       |
  410|  4.22k|   source.start_sequence().raw_bytes(bits).end_cons();
  411|       |
  412|  4.22k|   BER_Decoder sequence(bits, source.limits());
  413|       |
  414|  4.22k|   std::vector<std::vector<std::pair<OID, ASN1_String>>> rdns;
  415|       |
  416|       |   // Cap AVAs per RDN to bound work for downstream set-based matching.
  417|       |   // No legitimate cert has anywhere near this many AVAs in a single RDN.
  418|  4.22k|   constexpr size_t MAX_AVAS_PER_RDN = 32;
  419|       |
  420|  5.04k|   while(sequence.more_items()) {
  ------------------
  |  Branch (420:10): [True: 819, False: 4.22k]
  ------------------
  421|    819|      BER_Decoder rdn_decoder = sequence.start_set();
  422|       |
  423|    819|      std::vector<std::pair<OID, ASN1_String>> rdn;
  424|  2.02k|      while(rdn_decoder.more_items()) {
  ------------------
  |  Branch (424:13): [True: 1.20k, False: 819]
  ------------------
  425|  1.20k|         OID oid;
  426|  1.20k|         ASN1_String str;
  427|       |
  428|  1.20k|         rdn_decoder.start_sequence()
  429|  1.20k|            .decode(oid)
  430|  1.20k|            .decode(str)  // TODO support Any
  431|  1.20k|            .end_cons();
  432|       |
  433|  1.20k|         rdn.emplace_back(std::move(oid), std::move(str));
  434|       |
  435|  1.20k|         if(rdn.size() > MAX_AVAS_PER_RDN) {
  ------------------
  |  Branch (435:13): [True: 0, False: 1.20k]
  ------------------
  436|      0|            throw Decoding_Error("X.500 RDN has too many attribute-value assertions");
  437|      0|         }
  438|  1.20k|      }
  439|       |
  440|       |      /*
  441|       |      RFC 5280 4.1.2.4:
  442|       |         RelativeDistinguishedName ::=
  443|       |           SET SIZE (1..MAX) OF AttributeTypeAndValue
  444|       |      */
  445|    819|      if(rdn.empty()) {
  ------------------
  |  Branch (445:10): [True: 1, False: 818]
  ------------------
  446|      1|         throw Decoding_Error("X.500 RDN must contain at least one attribute-value assertion");
  447|      1|      }
  448|    818|      rdns.push_back(std::move(rdn));
  449|    818|   }
  450|       |
  451|  4.22k|   auto canonical_bits = canonicalize_dn(rdns);
  452|       |
  453|  4.22k|   m_rdn = std::move(rdns);
  454|  4.22k|   m_dn_bits = std::move(bits);
  455|  4.22k|   m_canonical_dn_bits = std::move(canonical_bits);
  456|  4.22k|}
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_115canonicalize_dnERKNSt3__16vectorINS2_INS1_4pairINS_3OIDENS_11ASN1_StringEEENS1_9allocatorIS6_EEEENS7_IS9_EEEE:
  310|  3.73k|std::vector<uint8_t> canonicalize_dn(const std::vector<std::vector<std::pair<OID, ASN1_String>>>& rdns) {
  311|  3.73k|   auto append_canonical_data = []<typename T>(std::vector<uint8_t>& out, const T& data) {
  312|  3.73k|      const std::array<uint8_t, 8> data_len = store_le(static_cast<uint64_t>(data.size()));
  313|  3.73k|      out.insert(out.end(), data_len.begin(), data_len.end());
  314|  3.73k|      out.insert(out.end(), data.begin(), data.end());
  315|  3.73k|   };
  316|       |
  317|  3.73k|   std::vector<uint8_t> canonical_bits;
  318|       |
  319|  3.73k|   for(const auto& rdn : rdns) {
  ------------------
  |  Branch (319:24): [True: 359, False: 3.73k]
  ------------------
  320|    359|      std::vector<uint8_t> rdn_bits;
  321|       |
  322|    939|      for(const auto& [oid, value] : canonicalize_rdn(rdn)) {
  ------------------
  |  Branch (322:36): [True: 939, False: 359]
  ------------------
  323|    939|         append_canonical_data(rdn_bits, oid.BER_encode());
  324|    939|         append_canonical_data(rdn_bits, value);
  325|    939|      }
  326|       |
  327|    359|      append_canonical_data(canonical_bits, rdn_bits);
  328|    359|   }
  329|       |
  330|  3.73k|   return canonical_bits;
  331|  3.73k|}
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_116canonicalize_rdnERKNSt3__16vectorINS1_4pairINS_3OIDENS_11ASN1_StringEEENS1_9allocatorIS6_EEEE:
  298|    359|std::vector<std::pair<OID, std::string>> canonicalize_rdn(const std::vector<std::pair<OID, ASN1_String>>& rdn) {
  299|    359|   std::vector<std::pair<OID, std::string>> result;
  300|    359|   result.reserve(rdn.size());
  301|    939|   for(const auto& ava : rdn) {
  ------------------
  |  Branch (301:24): [True: 939, False: 359]
  ------------------
  302|    939|      result.emplace_back(ava.first, X500_Char_Iterator::canonicalize(ava.second.value()));
  303|    939|   }
  304|    359|   if(result.size() != 1) {
  ------------------
  |  Branch (304:7): [True: 218, False: 141]
  ------------------
  305|    218|      std::sort(result.begin(), result.end());
  306|    218|   }
  307|    359|   return result;
  308|    359|}
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_118X500_Char_Iterator12canonicalizeENSt3__117basic_string_viewIcNS2_11char_traitsIcEEEE:
  114|    939|      static std::string canonicalize(std::string_view name) {
  115|    939|         std::string result;
  116|    939|         result.reserve(name.size());
  117|       |
  118|    939|         X500_Char_Iterator it(name);
  119|  8.66k|         while(auto c = it.next()) {
  ------------------
  |  Branch (119:21): [True: 7.72k, False: 939]
  ------------------
  120|  7.72k|            result += *c;
  121|  7.72k|         }
  122|       |
  123|    939|         return result;
  124|    939|      }
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_118X500_Char_IteratorC2ENSt3__117basic_string_viewIcNS2_11char_traitsIcEEEE:
   81|    939|      explicit X500_Char_Iterator(std::string_view s) : m_str(s), m_pos(0) {
   82|       |         // Skip leading whitespace
   83|  1.68k|         while(m_pos < m_str.size() && is_space(m_str[m_pos])) {
  ------------------
  |  Branch (83:16): [True: 1.27k, False: 412]
  |  Branch (83:40): [True: 749, False: 527]
  ------------------
   84|    749|            ++m_pos;
   85|    749|         }
   86|    939|      }
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_118X500_Char_Iterator4nextEv:
   89|  8.66k|      std::optional<char> next() {
   90|  8.66k|         if(m_pos >= m_str.size()) {
  ------------------
  |  Branch (90:13): [True: 869, False: 7.79k]
  ------------------
   91|    869|            return std::nullopt;
   92|    869|         }
   93|       |
   94|  7.79k|         if(is_space(m_str[m_pos])) {
  ------------------
  |  Branch (94:13): [True: 288, False: 7.51k]
  ------------------
   95|       |            // Skip the entire whitespace run
   96|  1.84k|            while(m_pos < m_str.size() && is_space(m_str[m_pos])) {
  ------------------
  |  Branch (96:19): [True: 1.77k, False: 70]
  |  Branch (96:43): [True: 1.55k, False: 218]
  ------------------
   97|  1.55k|               ++m_pos;
   98|  1.55k|            }
   99|       |            // Emit a single space only if more content follows (strip trailing ws)
  100|    288|            if(m_pos < m_str.size()) {
  ------------------
  |  Branch (100:16): [True: 218, False: 70]
  ------------------
  101|    218|               return ' ';
  102|    218|            }
  103|     70|            return std::nullopt;
  104|    288|         }
  105|       |
  106|  7.51k|         const char c = m_str[m_pos++];
  107|       |         // Locale-independent ASCII fold; RFC 5280 DN matching does not depend on libc locale
  108|  7.51k|         if(c >= 'A' && c <= 'Z') {
  ------------------
  |  Branch (108:13): [True: 637, False: 6.87k]
  |  Branch (108:25): [True: 254, False: 383]
  ------------------
  109|    254|            return static_cast<char>(c + ('a' - 'A'));
  110|    254|         }
  111|  7.25k|         return c;
  112|  7.51k|      }
x509_dn.cpp:_ZZN5Botan12_GLOBAL__N_115canonicalize_dnERKNSt3__16vectorINS2_INS1_4pairINS_3OIDENS_11ASN1_StringEEENS1_9allocatorIS6_EEEENS7_IS9_EEEEENK3$_0clINS2_IhNS7_IhEEEEEEDaRSH_RKT_:
  311|  1.29k|   auto append_canonical_data = []<typename T>(std::vector<uint8_t>& out, const T& data) {
  312|  1.29k|      const std::array<uint8_t, 8> data_len = store_le(static_cast<uint64_t>(data.size()));
  313|  1.29k|      out.insert(out.end(), data_len.begin(), data_len.end());
  314|  1.29k|      out.insert(out.end(), data.begin(), data.end());
  315|  1.29k|   };
x509_dn.cpp:_ZZN5Botan12_GLOBAL__N_115canonicalize_dnERKNSt3__16vectorINS2_INS1_4pairINS_3OIDENS_11ASN1_StringEEENS1_9allocatorIS6_EEEENS7_IS9_EEEEENK3$_0clINS1_12basic_stringIcNS1_11char_traitsIcEENS7_IcEEEEEEDaRNS2_IhNS7_IhEEEERKT_:
  311|    939|   auto append_canonical_data = []<typename T>(std::vector<uint8_t>& out, const T& data) {
  312|    939|      const std::array<uint8_t, 8> data_len = store_le(static_cast<uint64_t>(data.size()));
  313|    939|      out.insert(out.end(), data_len.begin(), data_len.end());
  314|    939|      out.insert(out.end(), data.begin(), data.end());
  315|    939|   };
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_18is_spaceEc:
   26|  10.8k|bool is_space(char c) {
   27|  10.8k|   return c == ' ' || c == '\t';
  ------------------
  |  Branch (27:11): [True: 1.34k, False: 9.50k]
  |  Branch (27:23): [True: 1.25k, False: 8.25k]
  ------------------
   28|  10.8k|}

_ZNK5Botan10Extensions13extension_setERKNS_3OIDE:
  235|  3.96k|bool Extensions::extension_set(const OID& oid) const {
  236|  3.96k|   return m_extension_info.contains(oid);
  237|  3.96k|}
_ZNK5Botan10Extensions20get_extension_objectERKNS_3OIDE:
  256|  14.5k|const Certificate_Extension* Extensions::get_extension_object(const OID& oid) const {
  257|  14.5k|   auto extn = m_extension_info.find(oid);
  258|  14.5k|   if(extn == m_extension_info.end()) {
  ------------------
  |  Branch (258:7): [True: 14.5k, False: 0]
  ------------------
  259|  14.5k|      return nullptr;
  260|  14.5k|   }
  261|       |
  262|      0|   return &extn->second.obj();
  263|  14.5k|}
_ZN5Botan10Extensions11decode_fromERNS_11BER_DecoderENSt3__18optionalINS_17Extension_ContextEEE:
  326|      1|void Extensions::decode_from(BER_Decoder& from_source, std::optional<Extension_Context> context) {
  327|      1|   m_extension_oids.clear();
  328|      1|   m_extension_info.clear();
  329|      1|   m_has_unknown_critical_extension = false;
  330|       |
  331|      1|   BER_Decoder sequence = from_source.start_sequence();
  332|       |
  333|      1|   while(sequence.more_items()) {
  ------------------
  |  Branch (333:10): [True: 0, False: 1]
  ------------------
  334|      0|      OID oid;
  335|      0|      bool critical = false;
  336|      0|      std::vector<uint8_t> bits;
  337|       |
  338|      0|      sequence.start_sequence()
  339|      0|         .decode(oid)
  340|      0|         .decode_optional(critical, ASN1_Type::Boolean, ASN1_Class::Universal, false)
  341|      0|         .decode(bits, ASN1_Type::OctetString)
  342|      0|         .end_cons();
  343|       |
  344|      0|      auto obj = create_extn_obj(oid, critical, bits, context);
  345|       |      // Unknown_Extension is the only Certificate_Extension with an empty oid_name
  346|      0|      if(critical && obj->oid_name().empty()) {
  ------------------
  |  Branch (346:10): [True: 0, False: 0]
  |  Branch (346:10): [True: 0, False: 0]
  |  Branch (346:22): [True: 0, False: 0]
  ------------------
  347|      0|         m_has_unknown_critical_extension = true;
  348|      0|      }
  349|      0|      Extensions_Info info(critical, std::move(bits), std::move(obj));
  350|       |
  351|      0|      m_extension_oids.push_back(oid);
  352|       |
  353|       |      // RFC 5280 4.2: "A certificate MUST NOT include more than one
  354|       |      // instance of a particular extension."
  355|      0|      if(!m_extension_info.emplace(std::move(oid), std::move(info)).second) {
  ------------------
  |  Branch (355:10): [True: 0, False: 0]
  ------------------
  356|      0|         throw Decoding_Error("Duplicate certificate extension encountered");
  357|      0|      }
  358|      0|   }
  359|      1|   sequence.verify_end();
  360|      1|}

_ZN5Botan11X509_Object9load_dataERNS_10DataSourceE:
   24|  2.92k|void X509_Object::load_data(DataSource& in) {
   25|  2.92k|   try {
   26|  2.92k|      if(ASN1::maybe_BER(in) && !PEM_Code::matches(in)) {
  ------------------
  |  Branch (26:10): [True: 2.74k, False: 174]
  |  Branch (26:33): [True: 2.72k, False: 26]
  ------------------
   27|  2.72k|         BER_Decoder dec(in, BER_Decoder::Limits::DER());
   28|  2.72k|         decode_from(dec);
   29|       |         // Call to verify_end omitted here since we have to sometimes decode
   30|       |         // multiple certificates encoded sequentially in a DataSource
   31|  2.72k|      } else {
   32|    200|         std::string got_label;
   33|    200|         DataSource_Memory ber(PEM_Code::decode(in, got_label));
   34|       |
   35|    200|         if(got_label != PEM_label()) {
  ------------------
  |  Branch (35:13): [True: 36, False: 164]
  ------------------
   36|     36|            bool is_alternate = false;
   37|     36|            for(const std::string_view alt_label : alternate_PEM_labels()) {
  ------------------
  |  Branch (37:50): [True: 36, False: 35]
  ------------------
   38|     36|               if(got_label == alt_label) {
  ------------------
  |  Branch (38:19): [True: 1, False: 35]
  ------------------
   39|      1|                  is_alternate = true;
   40|      1|                  break;
   41|      1|               }
   42|     36|            }
   43|       |
   44|     36|            if(!is_alternate) {
  ------------------
  |  Branch (44:16): [True: 35, False: 1]
  ------------------
   45|     35|               throw Decoding_Error("Unexpected PEM label for " + PEM_label() + " of " + got_label);
   46|     35|            }
   47|     36|         }
   48|       |
   49|    165|         BER_Decoder dec(ber, BER_Decoder::Limits::DER());
   50|    165|         decode_from(dec);
   51|       |         // Call to verify_end omitted here since we have to sometimes decode
   52|       |         // multiple certificates encoded sequentially in a DataSource
   53|    165|      }
   54|  2.92k|   } catch(Decoding_Error& e) {
   55|  1.54k|      throw Decoding_Error(PEM_label() + " decoding", e);
   56|  1.54k|   }
   57|  2.92k|}
_ZNK5Botan11X509_Object9signatureEv:
   59|  1.32k|const std::vector<uint8_t>& X509_Object::signature() const {
   60|  1.32k|   if(!m_signed_data) {
  ------------------
  |  Branch (60:7): [True: 0, False: 1.32k]
  ------------------
   61|      0|      throw Invalid_State("X509_Object uninitialized");
   62|      0|   }
   63|  1.32k|   return m_signed_data->m_sig;
   64|  1.32k|}
_ZNK5Botan11X509_Object11signed_bodyEv:
   66|  3.37k|const std::vector<uint8_t>& X509_Object::signed_body() const {
   67|  3.37k|   if(!m_signed_data) {
  ------------------
  |  Branch (67:7): [True: 0, False: 3.37k]
  ------------------
   68|      0|      throw Invalid_State("X509_Object uninitialized");
   69|      0|   }
   70|  3.37k|   return m_signed_data->m_tbs_bits;
   71|  3.37k|}
_ZNK5Botan11X509_Object19signature_algorithmEv:
   73|  2.68k|const AlgorithmIdentifier& X509_Object::signature_algorithm() const {
   74|  2.68k|   if(!m_signed_data) {
  ------------------
  |  Branch (74:7): [True: 0, False: 2.68k]
  ------------------
   75|      0|      throw Invalid_State("X509_Object uninitialized");
   76|      0|   }
   77|  2.68k|   return m_signed_data->m_sig_algo;
   78|  2.68k|}
_ZNK5Botan11X509_Object11encode_intoERNS_11DER_EncoderE:
   80|  1.32k|void X509_Object::encode_into(DER_Encoder& to) const {
   81|  1.32k|   to.start_sequence()
   82|  1.32k|      .start_sequence()
   83|  1.32k|      .raw_bytes(signed_body())
   84|  1.32k|      .end_cons()
   85|  1.32k|      .encode(signature_algorithm())
   86|  1.32k|      .encode_octet_aligned_bitstring(signature())
   87|  1.32k|      .end_cons();
   88|  1.32k|}
_ZN5Botan11X509_Object11decode_fromERNS_11BER_DecoderE:
   93|  2.72k|void X509_Object::decode_from(BER_Decoder& from) {
   94|  2.72k|   auto data = std::make_shared<Signed_Data>();
   95|       |
   96|  2.72k|   from.start_sequence()
   97|  2.72k|      .start_sequence()
   98|  2.72k|      .raw_bytes(data->m_tbs_bits)
   99|  2.72k|      .end_cons()
  100|  2.72k|      .decode(data->m_sig_algo)
  101|  2.72k|      .decode_octet_aligned_bitstring(data->m_sig)
  102|  2.72k|      .end_cons();
  103|       |
  104|  2.72k|   m_signed_data = std::move(data);
  105|  2.72k|   force_decode();
  106|  2.72k|}

_ZN5Botan18X509_Serial_NumberC2ERKNS_6BigIntE:
   20|  1.96k|X509_Serial_Number::X509_Serial_Number(const BigInt& value) : m_contents(ASN1::integer_contents(value)) {}
_ZNK5Botan18X509_Serial_Number11is_negativeEv:
   65|  1.31k|bool X509_Serial_Number::is_negative() const {
   66|  1.31k|   BOTAN_STATE_CHECK(!m_contents.empty());
  ------------------
  |  |   51|  1.31k|   do {                                                         \
  |  |   52|  1.31k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */             \
  |  |   53|  1.31k|      if(!(expr)) {                                             \
  |  |  ------------------
  |  |  |  Branch (53:10): [True: 0, False: 1.31k]
  |  |  ------------------
  |  |   54|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */    \
  |  |   55|      0|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   56|      0|      }                                                         \
  |  |   57|  1.31k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (57:12): [Folded, False: 1.31k]
  |  |  ------------------
  ------------------
   67|  1.31k|   return (m_contents[0] & 0x80) == 0x80;
   68|  1.31k|}
_ZNK5Botan18X509_Serial_Number7is_zeroEv:
   70|  1.33k|bool X509_Serial_Number::is_zero() const {
   71|  1.33k|   return m_contents.size() == 1 && m_contents[0] == 0x00;
  ------------------
  |  Branch (71:11): [True: 1.33k, False: 0]
  |  Branch (71:37): [True: 20, False: 1.31k]
  ------------------
   72|  1.33k|}
_ZNK5Botan18X509_Serial_Number9magnitudeEv:
   74|  1.33k|std::vector<uint8_t> X509_Serial_Number::magnitude() const {
   75|  1.33k|   BOTAN_STATE_CHECK(!m_contents.empty());
  ------------------
  |  |   51|  1.33k|   do {                                                         \
  |  |   52|  1.33k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */             \
  |  |   53|  1.33k|      if(!(expr)) {                                             \
  |  |  ------------------
  |  |  |  Branch (53:10): [True: 0, False: 1.33k]
  |  |  ------------------
  |  |   54|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */    \
  |  |   55|      0|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   56|      0|      }                                                         \
  |  |   57|  1.33k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (57:12): [Folded, False: 1.33k]
  |  |  ------------------
  ------------------
   76|       |
   77|  1.33k|   if(is_zero()) {
  ------------------
  |  Branch (77:7): [True: 20, False: 1.31k]
  ------------------
   78|     20|      return {};
   79|  1.31k|   } else if(is_negative()) {
  ------------------
  |  Branch (79:14): [True: 1.12k, False: 190]
  ------------------
   80|  1.12k|      return to_bigint().serialize();
   81|  1.12k|   } else if(m_contents[0] == 0x00) {
  ------------------
  |  Branch (81:14): [True: 0, False: 190]
  ------------------
   82|       |      // Positive value whose leading magnitude bit is set; skip the sign octet
   83|      0|      return {m_contents.begin() + 1, m_contents.end()};
   84|    190|   } else {
   85|    190|      return m_contents;
   86|    190|   }
   87|  1.33k|}
_ZNK5Botan18X509_Serial_Number9to_bigintEv:
   89|  1.12k|BigInt X509_Serial_Number::to_bigint() const {
   90|  1.12k|   BOTAN_STATE_CHECK(!m_contents.empty());
  ------------------
  |  |   51|  1.12k|   do {                                                         \
  |  |   52|  1.12k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */             \
  |  |   53|  1.12k|      if(!(expr)) {                                             \
  |  |  ------------------
  |  |  |  Branch (53:10): [True: 0, False: 1.12k]
  |  |  ------------------
  |  |   54|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */    \
  |  |   55|      0|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   56|      0|      }                                                         \
  |  |   57|  1.12k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (57:12): [Folded, False: 1.12k]
  |  |  ------------------
  ------------------
   91|  1.12k|   return ASN1::integer_from_contents(m_contents);
   92|  1.12k|}
_ZN5Botan18X509_Serial_Number11decode_fromERNS_11BER_DecoderE:
  108|  2.04k|void X509_Serial_Number::decode_from(BER_Decoder& from) {
  109|       |   // Decode via BigInt so the decoder's limits apply, in particular the
  110|       |   // rejection of non-minimal INTEGER encodings in DER mode
  111|  2.04k|   BigInt value;
  112|  2.04k|   from.decode(value);
  113|  2.04k|   *this = X509_Serial_Number(value);
  114|  2.04k|}

_ZN5Botan16X509_CertificateD2Ev:
   85|  1.32k|X509_Certificate::~X509_Certificate() = default;
_ZNK5Botan16X509_Certificate9PEM_labelEv:
   87|  1.61k|std::string X509_Certificate::PEM_label() const {
   88|  1.61k|   return "CERTIFICATE";
   89|  1.61k|}
_ZNK5Botan16X509_Certificate20alternate_PEM_labelsEv:
   91|     36|std::vector<std::string> X509_Certificate::alternate_PEM_labels() const {
   92|     36|   return {"X509 CERTIFICATE"};
   93|     36|}
_ZN5Botan16X509_CertificateC2ENSt3__14spanIKhLm18446744073709551615EEE:
   99|  2.92k|X509_Certificate::X509_Certificate(std::span<const uint8_t> in) {
  100|  2.92k|   DataSource_Memory src(in);
  101|  2.92k|   load_data(src);
  102|  2.92k|}
_ZN5Botan16X509_Certificate12force_decodeEv:
  367|  2.05k|void X509_Certificate::force_decode() {
  368|  2.05k|   m_data.reset();
  369|  2.05k|   m_data = parse_x509_cert_body(*this);
  370|  2.05k|}
_ZNK5Botan16X509_Certificate4dataEv:
  372|  1.32k|const X509_Certificate_Data& X509_Certificate::data() const {
  373|  1.32k|   if(m_data == nullptr) {
  ------------------
  |  Branch (373:7): [True: 0, False: 1.32k]
  ------------------
  374|      0|      throw Invalid_State("X509_Certificate uninitialized");
  375|      0|   }
  376|  1.32k|   return *m_data;
  377|  1.32k|}
_ZNK5Botan16X509_Certificate23subject_public_key_infoEv:
  411|  1.32k|const std::vector<uint8_t>& X509_Certificate::subject_public_key_info() const {
  412|  1.32k|   return data().m_subject_public_key_bits_seq;
  413|  1.32k|}
_ZNK5Botan16X509_Certificate18subject_public_keyEv:
  757|  1.32k|std::unique_ptr<Public_Key> X509_Certificate::subject_public_key() const {
  758|  1.32k|   try {
  759|  1.32k|      return std::unique_ptr<Public_Key>(X509::load_key(subject_public_key_info()));
  760|  1.32k|   } catch(std::exception& e) {
  761|  1.32k|      throw Decoding_Error("X509_Certificate::subject_public_key", e);
  762|  1.32k|   }
  763|  1.32k|}
x509cert.cpp:_ZN5Botan12_GLOBAL__N_120parse_x509_cert_bodyERKNS_11X509_ObjectE:
  113|  2.05k|std::unique_ptr<X509_Certificate_Data> parse_x509_cert_body(const X509_Object& obj) {
  114|  2.05k|   auto data = std::make_unique<X509_Certificate_Data>();
  115|       |
  116|  2.05k|   BER_Object public_key;
  117|  2.05k|   BER_Object v3_exts_data;
  118|       |
  119|  2.05k|   BER_Decoder(obj.signed_body(), BER_Decoder::Limits::DER())
  120|  2.05k|      .decode_optional(data->m_version, ASN1_Type(0), ASN1_Class::Constructed | ASN1_Class::ContextSpecific)
  121|  2.05k|      .decode(data->m_serial)
  122|  2.05k|      .decode(data->m_sig_algo_inner)
  123|  2.05k|      .decode(data->m_issuer_dn)
  124|  2.05k|      .start_sequence()
  125|  2.05k|      .decode(data->m_not_before)
  126|  2.05k|      .decode(data->m_not_after)
  127|  2.05k|      .end_cons()
  128|  2.05k|      .decode(data->m_subject_dn)
  129|  2.05k|      .get_next(public_key)
  130|  2.05k|      .decode_optional_string(data->m_v2_issuer_key_id, ASN1_Type::BitString, 1)
  131|  2.05k|      .decode_optional_string(data->m_v2_subject_key_id, ASN1_Type::BitString, 2)
  132|  2.05k|      .get_next(v3_exts_data)
  133|  2.05k|      .verify_end("TBSCertificate has extra data after extensions block");
  134|       |
  135|  2.05k|   if(data->m_version > 2) {
  ------------------
  |  Branch (135:7): [True: 0, False: 2.05k]
  ------------------
  136|      0|      throw Decoding_Error("Unknown X.509 cert version " + std::to_string(data->m_version));
  137|      0|   }
  138|  2.05k|   if(obj.signature_algorithm() != data->m_sig_algo_inner) {
  ------------------
  |  Branch (138:7): [True: 23, False: 2.03k]
  ------------------
  139|     23|      throw Decoding_Error("X.509 Certificate had differing algorithm identifiers in inner and outer ID fields");
  140|     23|   }
  141|       |
  142|  2.03k|   public_key.assert_is_a(ASN1_Type::Sequence, ASN1_Class::Constructed, "X.509 certificate public key");
  143|       |
  144|       |   // for general sanity convert wire version (0 based) to standards version (v1 .. v3)
  145|  2.03k|   data->m_version += 1;
  146|       |
  147|  2.03k|   data->m_serial_bits = data->m_serial.magnitude();
  148|  2.03k|   data->m_subject_dn_bits = ASN1::put_in_sequence(data->m_subject_dn.get_bits());
  149|  2.03k|   data->m_issuer_dn_bits = ASN1::put_in_sequence(data->m_issuer_dn.get_bits());
  150|       |
  151|  2.03k|   data->m_subject_public_key_bits.assign(public_key.bits(), public_key.bits() + public_key.length());
  152|       |
  153|  2.03k|   data->m_subject_public_key_bits_seq = ASN1::put_in_sequence(data->m_subject_public_key_bits);
  154|       |
  155|  2.03k|   BER_Decoder(data->m_subject_public_key_bits, BER_Decoder::Limits::DER())
  156|  2.03k|      .decode(data->m_subject_public_key_algid)
  157|  2.03k|      .decode_octet_aligned_bitstring(data->m_subject_public_key_bitstring)
  158|  2.03k|      .verify_end();
  159|       |
  160|  2.03k|   if(v3_exts_data.is_a(3, ASN1_Class::Constructed | ASN1_Class::ContextSpecific)) {
  ------------------
  |  Branch (160:7): [True: 1, False: 2.03k]
  ------------------
  161|       |      // Path validation will reject a v1/v2 cert with v3 extensions
  162|      1|      BER_Decoder cert_extensions(v3_exts_data, BER_Decoder::Limits::DER());
  163|      1|      data->m_v3_extensions.decode_from(cert_extensions, Extension_Context::Certificate);
  164|      1|      cert_extensions.verify_end();
  165|  2.03k|   } else if(v3_exts_data.is_set()) {
  ------------------
  |  Branch (165:14): [True: 5, False: 2.02k]
  ------------------
  166|      5|      throw BER_Bad_Tag("Unknown tag in X.509 cert", v3_exts_data.tagging());
  167|      5|   }
  168|       |
  169|       |   // Now cache some fields from the extensions
  170|  2.02k|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Key_Usage>()) {
  ------------------
  |  Branch (170:19): [True: 0, False: 2.02k]
  ------------------
  171|      0|      data->m_key_constraints = ext->get_constraints();
  172|       |      /*
  173|       |      RFC 5280: When the keyUsage extension appears in a certificate,
  174|       |      at least one of the bits MUST be set to 1.
  175|       |      */
  176|      0|      if(data->m_key_constraints.empty()) {
  ------------------
  |  Branch (176:10): [True: 0, False: 0]
  ------------------
  177|      0|         throw Decoding_Error("Certificate has invalid encoding for KeyUsage");
  178|      0|      }
  179|      0|   }
  180|       |
  181|  2.02k|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Subject_Key_ID>()) {
  ------------------
  |  Branch (181:19): [True: 0, False: 2.02k]
  ------------------
  182|      0|      data->m_subject_key_id = ext->get_key_id();
  183|      0|   }
  184|       |
  185|  2.02k|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Authority_Key_ID>()) {
  ------------------
  |  Branch (185:19): [True: 0, False: 2.02k]
  ------------------
  186|      0|      data->m_authority_key_id = ext->get_key_id();
  187|      0|   }
  188|       |
  189|  2.02k|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Name_Constraints>()) {
  ------------------
  |  Branch (189:19): [True: 0, False: 2.02k]
  ------------------
  190|      0|      data->m_name_constraints = ext->get_name_constraints();
  191|      0|   }
  192|       |
  193|  2.02k|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Extended_Key_Usage>()) {
  ------------------
  |  Branch (193:19): [True: 0, False: 2.02k]
  ------------------
  194|      0|      data->m_extended_key_usage = ext->object_identifiers();
  195|       |      /*
  196|       |      RFC 5280 section 4.2.1.12
  197|       |
  198|       |      "This extension indicates one or more purposes ..."
  199|       |
  200|       |      "If the extension is present, then the certificate MUST only be
  201|       |      used for one of the purposes indicated."
  202|       |
  203|       |      Thus we reject an EKU extension which is empty, since this indicates
  204|       |      the certificate cannot be used for any purpose.
  205|       |      */
  206|      0|      if(data->m_extended_key_usage.empty()) {
  ------------------
  |  Branch (206:10): [True: 0, False: 0]
  ------------------
  207|      0|         throw Decoding_Error("Certificate has invalid empty EKU extension");
  208|      0|      }
  209|      0|   }
  210|       |
  211|  2.02k|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Basic_Constraints>()) {
  ------------------
  |  Branch (211:19): [True: 0, False: 2.02k]
  ------------------
  212|       |      /*
  213|       |      * RFC 5280 4.2.1.9 requires that conforming CAs "MUST mark the
  214|       |      * extension [basicConstraints] as critical in such certificates"
  215|       |      * but places no such requirement on validators.
  216|       |      */
  217|      0|      if(ext->is_ca() == true) {
  ------------------
  |  Branch (217:10): [True: 0, False: 0]
  ------------------
  218|       |         /*
  219|       |         * RFC 5280 section 4.2.1.3 requires that CAs include KeyUsage in all
  220|       |         * intermediate CA certificates they issue. Currently we accept it being
  221|       |         * missing, as do most other implementations. But it may be worth
  222|       |         * removing this entirely, or alternately adding a warning level
  223|       |         * validation failure for it.
  224|       |         */
  225|      0|         const bool allowed_by_ku =
  226|      0|            data->m_key_constraints.includes(Key_Constraints::KeyCertSign) || data->m_key_constraints.empty();
  ------------------
  |  Branch (226:13): [True: 0, False: 0]
  |  Branch (226:79): [True: 0, False: 0]
  ------------------
  227|       |
  228|       |         /*
  229|       |         * If the extended key usages are set then we must restrict the usage in
  230|       |         * accordance with it as well.
  231|       |         *
  232|       |         * RFC 5280 does not define any extended key usages compatible with certificate
  233|       |         * signing, but some CAs use serverAuth, clientAuth, OCSPSigning, or AnyExtendedKeyUsage
  234|       |         * for this purpose, even though clearly all of these (besides AEKU) are invalid.
  235|       |         * This check at least allows excluding a certificate which is set for only eg
  236|       |         * timestamping or code signing, and that seems about the best we can possibly enforce.
  237|       |         * OpenSSL, BoringSSL, and Go all completely ignore EKUs in determining ability to
  238|       |         * issue certs.
  239|       |         */
  240|      0|         const bool allowed_by_ext_ku = [](const std::vector<OID>& ext_ku) -> bool {
  241|      0|            if(ext_ku.empty()) {
  242|      0|               return true;
  243|      0|            }
  244|       |
  245|      0|            const auto server_auth = OID::from_name("PKIX.ServerAuth");
  246|      0|            const auto client_auth = OID::from_name("PKIX.ClientAuth");
  247|      0|            const auto ocsp_sign = OID::from_name("PKIX.OCSPSigning");
  248|      0|            const auto any_eku = OID::from_name("X509v3.AnyExtendedKeyUsage");
  249|       |
  250|      0|            for(const auto& oid : ext_ku) {
  251|      0|               if(oid == any_eku || oid == server_auth || oid == client_auth || oid == ocsp_sign) {
  252|      0|                  return true;
  253|      0|               }
  254|      0|            }
  255|       |
  256|      0|            return false;
  257|      0|         }(data->m_extended_key_usage);
  258|       |
  259|      0|         if(allowed_by_ku && allowed_by_ext_ku) {
  ------------------
  |  Branch (259:13): [True: 0, False: 0]
  |  Branch (259:30): [True: 0, False: 0]
  ------------------
  260|      0|            data->m_is_ca_certificate = true;
  261|      0|            data->m_path_len_constraint = ext->path_length_constraint();
  262|      0|         }
  263|      0|      }
  264|      0|   }
  265|       |
  266|  2.02k|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Issuer_Alternative_Name>()) {
  ------------------
  |  Branch (266:19): [True: 0, False: 2.02k]
  ------------------
  267|      0|      data->m_issuer_alt_name = ext->get_alt_name();
  268|      0|   }
  269|       |
  270|  2.02k|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Subject_Alternative_Name>()) {
  ------------------
  |  Branch (270:19): [True: 0, False: 2.02k]
  ------------------
  271|      0|      data->m_subject_alt_name = ext->get_alt_name();
  272|      0|   }
  273|       |
  274|       |   // This will be set even if SAN parsing failed entirely eg due to a decoding error
  275|       |   // or if the SAN is empty. This is used to guard against using the CN for domain
  276|       |   // name checking.
  277|  2.02k|   const auto san_oid = OID::from_string("X509v3.SubjectAlternativeName");
  278|  2.02k|   data->m_subject_alt_name_exists = data->m_v3_extensions.extension_set(san_oid);
  279|       |
  280|       |   /*
  281|       |   * RFC 9608 Section 4:
  282|       |   *
  283|       |   *   If the noRevAvail certificate extension specified in this document is
  284|       |   *   present or the ocsp-nocheck certificate extension [RFC6960] is
  285|       |   *   present, then Step (a)(3) is skipped.  Otherwise, revocation status
  286|       |   *   determination of the certificate is performed.
  287|       |   */
  288|  2.02k|   data->m_skip_revocation_check =
  289|  2.02k|      data->m_v3_extensions.extension_set(Cert_Extension::NoRevocationAvailable::static_oid()) ||
  ------------------
  |  Branch (289:7): [True: 708, False: 1.32k]
  ------------------
  290|  1.32k|      data->m_v3_extensions.extension_set(Cert_Extension::OCSP_NoCheck::static_oid());
  ------------------
  |  Branch (290:7): [True: 0, False: 1.32k]
  ------------------
  291|       |
  292|  2.02k|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Certificate_Policies>()) {
  ------------------
  |  Branch (292:19): [True: 0, False: 2.02k]
  ------------------
  293|      0|      data->m_cert_policies = ext->get_policy_oids();
  294|      0|   }
  295|       |
  296|  2.02k|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Authority_Information_Access>()) {
  ------------------
  |  Branch (296:19): [True: 0, False: 2.02k]
  ------------------
  297|      0|      data->m_ocsp_responders = ext->ocsp_responder_uris();
  298|      0|      data->m_ca_issuers = ext->ca_issuer_uris();
  299|      0|   }
  300|       |
  301|  2.02k|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::CRL_Distribution_Points>()) {
  ------------------
  |  Branch (301:19): [True: 0, False: 2.02k]
  ------------------
  302|      0|      data->m_crl_distribution_points = ext->crl_distribution_point_uris();
  303|      0|   }
  304|       |
  305|       |   /*
  306|       |   Determine if this certificate appears to be self-issued (subject == issuer).
  307|       |   This is only a heuristic used for path building so it's ok it is not precise.
  308|       |   The self-signature is verified during path validation.
  309|       |   */
  310|  2.02k|   if(data->m_subject_dn == data->m_issuer_dn) {
  ------------------
  |  Branch (310:7): [True: 1.32k, False: 708]
  ------------------
  311|  1.32k|      if(!data->m_subject_key_id.empty() && !data->m_authority_key_id.empty()) {
  ------------------
  |  Branch (311:10): [True: 0, False: 1.32k]
  |  Branch (311:45): [True: 0, False: 0]
  ------------------
  312|       |         /*
  313|       |         Both SKID and AKID are set so we can reliably determine self-signed vs
  314|       |         self-issued by comparing the two
  315|       |         */
  316|      0|         data->m_self_signed = (data->m_subject_key_id == data->m_authority_key_id);
  317|  1.32k|      } else {
  318|       |         /*
  319|       |         Without both SKID and AKID we can't determine with certainty. Assume
  320|       |         self-signed since that's by far the common case.
  321|       |         */
  322|  1.32k|         data->m_self_signed = true;
  323|  1.32k|      }
  324|  1.32k|   }
  325|       |
  326|  2.02k|   const std::vector<uint8_t> full_encoding = obj.BER_encode();
  327|       |
  328|  2.02k|   if(auto sha1 = HashFunction::create("SHA-1")) {
  ------------------
  |  Branch (328:12): [True: 1.32k, False: 708]
  ------------------
  329|  1.32k|      sha1->update(data->m_subject_public_key_bitstring);
  330|  1.32k|      data->m_subject_public_key_bitstring_sha1 = sha1->final_stdvec();
  331|       |      // otherwise left as empty, and we will throw if subject_public_key_bitstring_sha1 is called
  332|       |
  333|  1.32k|      sha1->update(full_encoding);
  334|  1.32k|      sha1->final(data->m_cert_data_sha1);
  335|  1.32k|      data->m_fingerprint_sha1 = format_hex_fingerprint(data->m_cert_data_sha1);
  336|       |
  337|  1.32k|      sha1->update(data->m_issuer_dn_bits);
  338|  1.32k|      sha1->final(data->m_issuer_dn_bits_sha1);
  339|       |
  340|  1.32k|      sha1->update(data->m_subject_dn_bits);
  341|  1.32k|      sha1->final(data->m_subject_dn_bits_sha1);
  342|  1.32k|   }
  343|       |
  344|       |   // SHA-256 is a hard dependency of this module
  345|  2.02k|   auto sha256 = HashFunction::create_or_throw("SHA-256");
  346|  2.02k|   sha256->update(data->m_issuer_dn_bits);
  347|  2.02k|   data->m_issuer_dn_bits_sha256 = sha256->final_stdvec();
  348|       |
  349|  2.02k|   sha256->update(data->m_subject_dn_bits);
  350|  2.02k|   data->m_subject_dn_bits_sha256 = sha256->final_stdvec();
  351|       |
  352|  2.02k|   sha256->update(full_encoding);
  353|  2.02k|   sha256->final(data->m_cert_data_sha256);
  354|  2.02k|   data->m_fingerprint_sha256 = format_hex_fingerprint(data->m_cert_data_sha256);
  355|       |
  356|  2.02k|   sha256->update(data->m_subject_public_key_bitstring);
  357|  2.02k|   sha256->final(data->m_subject_public_key_bitstring_sha256);
  358|       |
  359|  2.02k|   return data;
  360|  2.02k|}

